Vulnerability index

Browse CVEs

5,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.8 CVE-2026-13717 A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard… No fix yet Fix from $4,9002026-08-10 MEDIUM 6.5 CVE-2026-72585 An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.1 CVE-2026-72575 An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, create, update, and delete usergr… No fix yet Fix from $5,7502026-08-10 MEDIUM 6.9 CVE-2026-21084 Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. No fix yet Fix from $4,0002026-08-10 MEDIUM 5.5 CVE-2026-21064 Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. Android No fix yet Fix from $4,0002026-08-10 HIGH 8.8 CVE-2026-17540 The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a s… No fix yet Fix from $4,9002026-08-10 MEDIUM 5.3 CVE-2026-17012 The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.3 CVE-2026-19358 A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation ca… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19357 A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19356 A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-md… No fix yet Fix from $4,0002026-08-09 HIGH 8.1 CVE-2026-16948 The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects … No fix yet Fix from $1,9502026-08-08 MEDIUM 6.3 CVE-2026-19210 A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?ac… No fix yet Fix from $1,6002026-08-07 HIGH 8.7 CVE-2026-66494 Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.2 CVE-2026-54213 Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/inter… No fix yet Fix from $2,3002026-08-07 HIGH 8.5 CVE-2026-54208 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write … No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-12261 A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts pa… No fix yet Fix from $1,6002026-08-07 HIGH 7.8 CVE-2026-19192 A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\… No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-19193 A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter … No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-19195 A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the co… No fix yet Fix from $1,9502026-08-07 HIGH 8.8 CVE-2026-65668 Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. Purview Ediscovery No fix yet Fix from $1,9502026-08-07 CRITICAL 9.6 CVE-2026-56161 Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Azure Logic Apps No fix yet Fix from $2,3002026-08-07 HIGH 8.8 CVE-2026-67687 Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleContro… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-19065 A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of t… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.0 CVE-2025-14561 In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing suffici… No fix yet Fix from $2,3002026-08-06 MEDIUM 5.2 CVE-2026-55979 An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is l… No fix yet Fix from $1,6002026-08-06 HIGH 8.4 CVE-2026-55978 An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter co… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.4 CVE-2026-13703 The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any l… No fix yet Fix from $1,6002026-08-06 HIGH 8.2 CVE-2026-14829 The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-18993 A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-18974 A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the compon… No fix yet Fix from $1,6002026-08-06