Vulnerability index

Browse CVEs

5,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.3 CVE-2026-18969 A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the fi… No fix yet Fix from $1,9502026-08-06 HIGH 8.1 CVE-2025-63822 SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters t… No fix yet Fix from $1,9502026-08-05 MEDIUM 5.4 CVE-2026-70612 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b… No fix yet Fix from $1,6002026-08-05 HIGH 8.1 CVE-2026-10547 IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing… Langflow 1.11.0+ Fix from $1,9502026-08-05 CRITICAL 9.9 CVE-2026-20304 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.0 CVE-2026-20267 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen… Ios Xe No fix yet Fix from $2,3002026-08-05 MEDIUM 6.3 CVE-2026-18927 A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.6 CVE-2026-70602 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b… No fix yet Fix from $1,6002026-08-05 HIGH 8.1 CVE-2026-16102 A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy f… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2025-70962 Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication me… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.2 CVE-2026-71204 changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application setti… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-16736 The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registrat… No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-15230 The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, a… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-67979 Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary … No fix yet Fix from $2,3002026-08-04 MEDIUM 5.4 CVE-2026-70481 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update an… No fix yet Fix from $1,6002026-08-04 HIGH 8.3 CVE-2026-70476 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in pa… No fix yet Fix from $1,9502026-08-04 HIGH 7.3 CVE-2026-18788 A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager… No fix yet Fix from $1,9502026-08-04 MEDIUM 5.9 CVE-2026-16547 The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.5 CVE-2026-14816 The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording… No fix yet Fix from $1,6002026-08-04 MEDIUM 5.4 CVE-2026-14848 The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription… No fix yet Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-67970 Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal. No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67975 Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add… No fix yet Fix from $1,9502026-08-03 HIGH 7.8 CVE-2026-59912 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged atta… Display And Peripheral Manager 2.3.0.1005+ Fix from $1,9502026-08-03 MEDIUM 6.2 CVE-2026-15430 Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged … No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-56608 HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users t… Icontrol No fix yet Fix from $1,6002026-08-03 MEDIUM 6.5 CVE-2026-16563 The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through i… No fix yet Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-15241 The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing … No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-15151 The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users … No fix yet Fix from $1,9502026-08-02 MEDIUM 6.5 CVE-2026-14315 The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing una… No fix yet Fix from $1,6002026-08-01 MEDIUM 5.3 CVE-2026-14822 The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endp… No fix yet Fix from $1,6002026-08-01