Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2026-36035 Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticat… Mitigation only Fix from $1,6002026-07-14 HIGH 8.8 CVE-2026-47301 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. Configuration Manager 2503 Mitigation only Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-58617 Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. 365 Copilot 2.111.4+ Fix from $2,3002026-07-14 MEDIUM 5.5 CVE-2026-58545 Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-57088 Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.20348.5386+ Fix from $1,9502026-07-14 MEDIUM 5.4 CVE-2026-56157 Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50495 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 HIGH 7.1 CVE-2026-50465 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. Windows 11 24h2 10.0.26100.8875 / 10.0.26100.33158+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50423 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,9502026-07-14 MEDIUM 6.1 CVE-2026-50418 Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. Windows 11 24h2 10.0.20348.5386 / 10.0.26100.8875+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-50373 Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50335 Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-55014 Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. Remote Help 5.2.1037.0+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-50342 Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.8875 / 10.0.26200.8875+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50351 Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50311 Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.0 CVE-2026-50325 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.0 CVE-2026-50297 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.0 CVE-2026-49805 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.3 CVE-2026-15677 A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a… Mitigation only Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-57855 Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/C… Patch available Fix from $1,9502026-07-13 CRITICAL 9.1 CVE-2026-51538 EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When th… Opener Mitigation only Fix from $2,3002026-07-13 MEDIUM 5.3 CVE-2026-15530 A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=… Mitigation only Fix from $1,6002026-07-13 HIGH 7.3 CVE-2026-15488 A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller… Patch available Fix from $1,9502026-07-12 MEDIUM 5.3 CVE-2026-15476 A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of … Mitigation only Fix from $1,6002026-07-12 MEDIUM 5.3 CVE-2026-15475 A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the… Mitigation only Fix from $1,6002026-07-12 CRITICAL 9.8 CVE-2026-20744 The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation. Mitigation only Fix from $2,3002026-07-10 MEDIUM 6.5 CVE-2026-56335 Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration … Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.5 CVE-2026-40009 Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by re… Mitigation only Fix from $1,6002026-07-10 HIGH 7.5 CVE-2026-40452 Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value dat… Mitigation only Fix from $1,9502026-07-10