Vulnerability index

Browse CVEs

5,746 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.3 CVE-2026-16331 A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such ma… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16327 A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a … No fix yet Fix from $1,9502026-07-21 HIGH 7.6 CVE-2026-55544 NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write oper… No fix yet Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-55550 NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal appli… No fix yet Fix from $1,9502026-07-20 HIGH 8.2 CVE-2026-47255 AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0… Patch available Fix from $1,9502026-07-20 HIGH 7.3 CVE-2026-16324 A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qna… No fix yet Fix from $1,9502026-07-20 CRITICAL 9.1 CVE-2026-62414 Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply ac… Mitigation only Fix from $2,3002026-07-20 HIGH 8.7 CVE-2026-60030 Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder … No fix yet Fix from $1,9502026-07-20 HIGH 8.2 CVE-2026-46415 The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to vers… Patch available Fix from $1,9502026-07-20 MEDIUM 5.3 CVE-2026-12972 The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions ava… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.3 CVE-2026-16201 A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of… No fix yet Fix from $1,6002026-07-19 MEDIUM 6.5 CVE-2026-51083 Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privilege… No fix yet Fix from $1,6002026-07-17 CRITICAL 9.9 CVE-2026-54526 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow… Argo Workflows 3.7.15 / 4.0.6+ Fix from $2,3002026-07-16 HIGH 8.1 CVE-2026-46353 BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUr… Patch available Fix from $1,9502026-07-16 MEDIUM 6.3 CVE-2026-35148 HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form… Dfx Server after 2.5 Fix from $1,6002026-07-16 HIGH 8.1 CVE-2026-1609 A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak f… Build Of Keycloak No fix yet Fix from $1,9502026-07-16 MEDIUM 5.8 CVE-2026-62314 Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.… Patch available Fix from $1,6002026-07-15 HIGH 8.5 CVE-2026-55234 Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.j… Patch available Fix from $1,9502026-07-15 HIGH 7.7 CVE-2026-45313 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc… Mitigation only Fix from $1,9502026-07-15 HIGH 8.2 CVE-2026-46485 Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated … Mitigation only Fix from $1,9502026-07-15 CRITICAL 9.8 CVE-2026-14960 Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including… Mitigation only Fix from $2,3002026-07-15 HIGH 8.8 CVE-2026-20150 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte… Roomos 11.32.6.0 / 11.39.1.1+ Fix from $1,9502026-07-15 HIGH 7.7 CVE-2026-47164 Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only… Patch available Fix from $1,9502026-07-15 MEDIUM 6.5 CVE-2026-36035 Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticat… Mitigation only Fix from $1,6002026-07-14 HIGH 8.8 CVE-2026-47301 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. Configuration Manager 2503 Mitigation only Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-58617 Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. 365 Copilot 2.111.4+ Fix from $2,3002026-07-14 MEDIUM 5.5 CVE-2026-58545 Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-57088 Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.20348.5386+ Fix from $1,9502026-07-14 MEDIUM 5.4 CVE-2026-56157 Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50495 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14