Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.3 CVE-2026-15319 A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/a… Patch available Fix from $1,9502026-07-10 HIGH 8.1 CVE-2025-45422 Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port f… Mitigation only Fix from $1,9502026-07-09 HIGH 7.5 CVE-2025-63579 Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts in… Mitigation only Fix from $1,9502026-07-09 HIGH 7.5 CVE-2026-59720 Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPubl… Patch available Fix from $1,9502026-07-09 MEDIUM 6.3 CVE-2026-15188 A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is t… Mitigation only Fix from $1,6002026-07-09 HIGH 8.2 CVE-2026-58525 Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. Edge Chromium 150.0.4078.50+ Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-48955 An improper access check allows unauthorized users to access workflow stage and transition information. Joomla\! 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 5.0 CVE-2026-48956 An improper access check allows users to display a list of modules in the frontend. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 HIGH 8.8 CVE-2026-48957 An improper access check allows unauthorized users to access com_privacy datasets. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,9502026-07-07 HIGH 8.8 CVE-2026-48958 An improper access check allows unauthorized users to create custom fields via webservices endpoints. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,9502026-07-07 HIGH 8.8 CVE-2026-48948 An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,9502026-07-07 HIGH 8.5 CVE-2026-54765 Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve tw… Traefik 3.7.6+ Fix from $1,9502026-07-06 CRITICAL 9.8 CVE-2026-48204 Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs produce… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-24014 Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici… Iotdb 2.0.8+ Fix from $2,3002026-07-06 MEDIUM 6.5 CVE-2026-14792 A security vulnerability has been detected in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/modules/survey/link/actions.ts … Patch available Fix from $1,6002026-07-06 MEDIUM 6.3 CVE-2026-14777 A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functiona… Mitigation only Fix from $1,6002026-07-06 MEDIUM 6.3 CVE-2026-14775 A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /pro… Mitigation only Fix from $1,6002026-07-05 MEDIUM 6.3 CVE-2026-14776 A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the funct… Mitigation only Fix from $1,6002026-07-05 HIGH 8.8 CVE-2026-9085 Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institu… Mitigation only Fix from $1,9502026-07-05 HIGH 7.3 CVE-2026-14736 A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. The impacted element is an unknown function of the file user_auth_commit.php. Perform… Mitigation only Fix from $1,9502026-07-05 MEDIUM 6.3 CVE-2026-14698 A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown functio… Mitigation only Fix from $1,6002026-07-05 HIGH 8.8 CVE-2025-71380 The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user acces… Mitigation only Fix from $1,9502026-07-04 MEDIUM 6.5 CVE-2026-58523 Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03 HIGH 7.5 CVE-2026-58421 Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service Patch available Fix from $1,9502026-07-03 CRITICAL 9.8 CVE-2026-58422 Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts Patch available Fix from $2,3002026-07-03 MEDIUM 6.9 CVE-2026-58286 Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03 MEDIUM 6.9 CVE-2026-58282 Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03 HIGH 7.5 CVE-2026-27779 Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generatio… Patch available Fix from $1,9502026-07-03 HIGH 8.1 CVE-2026-28699 Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication. Patch available Fix from $1,9502026-07-03 CRITICAL 9.1 CVE-2026-26247 Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the… Patch available Fix from $2,3002026-07-03