Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2026-26292 Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration tran… Patch available Fix from $2,3002026-07-03 HIGH 7.5 CVE-2026-27660 Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission. Patch available Fix from $1,9502026-07-03 HIGH 8.1 CVE-2026-22555 Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can ex… Patch available Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-24451 Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no… Patch available Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-24690 Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches. Patch available Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-25712 Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations. Patch available Fix from $1,9502026-07-03 CRITICAL 9.1 CVE-2026-20706 Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint. Patch available Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-20896EPSS 62% Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user w… Patch available Fix from $2,3002026-07-03 MEDIUM 5.3 CVE-2026-20909 Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. Patch available Fix from $1,6002026-07-03 MEDIUM 5.4 CVE-2026-14614 A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue al… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $1,6002026-07-03 CRITICAL 9.8 CVE-2026-26145 Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. Azure Synapse No fix yet Fix from $2,3002026-07-02 HIGH 8.8 CVE-2026-55112 A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability f… Unifi Dream Machine Pro Firmware after 5.1.15 Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-55114 A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Applica… Unifi Network Application 10.4.57+ Fix from $1,9502026-07-02 CRITICAL 9.8 CVE-2026-55116 A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in… Unifi Connect 3.4.20+ Fix from $2,3002026-07-02 HIGH 8.3 CVE-2026-55118 A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found… Unifi Network Application 10.4.57+ Fix from $1,9502026-07-02 HIGH 8.1 CVE-2026-55119 A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Applicatio… Unifi Talk Application 5.2.2+ Fix from $1,9502026-07-02 HIGH 8.6 CVE-2026-54407 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth… Unifi Protect 7.1.83+ Fix from $1,9502026-07-02 CRITICAL 9.8 CVE-2026-54408 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth… Unifi Protect 7.1.83+ Fix from $2,3002026-07-02 CRITICAL 9.1 CVE-2026-54400 A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Applica… Unifi Access 4.2.29+ Fix from $2,3002026-07-02 CRITICAL 10.0 CVE-2026-50746 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a C… Unifi Connect Application 3.24.20+ Fix from $2,3002026-07-02 HIGH 8.1 CVE-2026-8147 In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allo… Mlflow 3.14.0+ Fix from $1,9502026-07-02 MEDIUM 6.0 CVE-2026-50280 Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::actionMoveToSection() endpoin… Patch available Fix from $1,6002026-07-02 MEDIUM 6.5 CVE-2026-14155 Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-14156 Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-14061 Inappropriate implementation in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information fr… Chrome 150.0.7871.46+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-14035 Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive inform… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13954 Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive i… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13964 Insufficient policy enforcement in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrict… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13949 Insufficient policy enforcement in Payments in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensit… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13953 Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process … Chrome 150.0.7871.47+ Fix from $1,6002026-06-30