Vulnerability index

Browse CVEs

5,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.2 CVE-2026-59501 CWE-284: Improper Access Control No fix yet Fix from $4,9002026-08-13 HIGH 8.6 CVE-2026-59505 CWE-284: Improper Access Control No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-13328 The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is als… No fix yet Fix from $4,0002026-08-13 HIGH 7.8 CVE-2026-13367 IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. Informix Dynamic Server No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-59914 Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low pri… Display And Peripheral Manager No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-59917 Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attac… Display And Peripheral Manager No fix yet Fix from $4,9002026-08-12 MEDIUM 6.3 CVE-2026-67287 Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on … No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-67284 Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform vario… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.9 CVE-2026-67283 Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform var… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.1 CVE-2026-16538 The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wall… No fix yet Fix from $5,7502026-08-12 HIGH 8.2 CVE-2026-13171 The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticate… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-73212 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_i… No fix yet Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-66804 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. Windows 10 22h2 10.0.19045.7663 / 10.0.26100.9106+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65773 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-65675 No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. Github Copilot Chat No fix yet Fix from $4,0002026-08-11 HIGH 8.5 CVE-2026-20898 Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of pri… No fix yet Fix from $4,9002026-08-11 HIGH 8.4 CVE-2026-20789 Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privileg… No fix yet Fix from $4,9002026-08-11 HIGH 8.3 CVE-2026-20741 Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Unprivileged sof… No fix yet Fix from $4,9002026-08-11 HIGH 7.2 CVE-2026-20716 Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-72600 A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-72601 A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally iden… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-72561 A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfi… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-72563 A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to oth… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-72595 A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to othe… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-72596 A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The … No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-72554 A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations … No fix yet Fix from $4,0002026-08-11 HIGH 8.1 CVE-2026-72555 A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to fal… No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-72693 `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `k… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-72909 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions pa… No fix yet Fix from $4,9002026-08-10 HIGH 8.8 CVE-2026-18951 A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` manageme… No fix yet Fix from $4,9002026-08-10