Vulnerability index

Browse CVEs

5,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.9 CVE-2026-66780 A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses exce… Fix unknown Fix from $5,7502026-08-18 MEDIUM 5.1 CVE-2026-73372 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access che… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.1 CVE-2026-72531 Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check … Fix unknown Fix from $4,0002026-08-18 HIGH 8.6 CVE-2026-54730 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow with… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-73371 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthori… Fix unknown Fix from $4,0002026-08-18 HIGH 8.5 CVE-2026-71574 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check a… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-72532 Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allow… Fix unknown Fix from $4,0002026-08-18 HIGH 8.1 CVE-2026-50138 goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `-… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-74979 Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird … Fix unknown Fix from $5,7502026-08-18 MEDIUM 6.3 CVE-2024-14046 A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/contro… Fix unknown Fix from $4,0002026-08-18 CRITICAL 9.8 CVE-2026-42163 Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain c… Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-68004 An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-lev… Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-73061 Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties… No fix yet Fix from $5,7502026-08-16 MEDIUM 6.5 CVE-2026-19711 The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allow… Fix unknown Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19918 A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Manag… No fix yet Fix from $4,0002026-08-16 MEDIUM 5.3 CVE-2026-14229 The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of… Fix unknown Fix from $4,0002026-08-15 MEDIUM 5.1 CVE-2026-71570 Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_ic… No fix yet Fix from $4,0002026-08-14 HIGH 8.8 CVE-2026-72837 File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers wi… No fix yet Fix from $4,9002026-08-14 HIGH 8.6 CVE-2026-73664 FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administ… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.8 CVE-2026-58440 Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplet… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-58507 Private Repository Existence Disclosure via go-get Meta Endpoint No fix yet Fix from $4,0002026-08-13 CRITICAL 9.1 CVE-2026-58508 Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) No fix yet Fix from $5,7502026-08-13 HIGH 7.1 CVE-2026-58437 Repository Visibility Manipulation via Git Push Options No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-58439 Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-58417 REST API exposes organization membership of private organizations to public No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-56654 Privilege Escalation via Access Token Scope Escalation in API No fix yet Fix from $5,7502026-08-13 MEDIUM 6.2 CVE-2026-56657 Gitea SSH Key Parser Denial of Service No fix yet Fix from $4,0002026-08-13 CRITICAL 9.1 CVE-2026-56750 Gitea Remember-Me Token Theft Not Invalidating Attacker Session No fix yet Fix from $5,7502026-08-13 MEDIUM 6.2 CVE-2026-56755 Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload No fix yet Fix from $4,0002026-08-13 MEDIUM 5.4 CVE-2026-55986 Email Management API Bypasses ManageCredentials Feature Restrictions No fix yet Fix from $4,0002026-08-13