Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2026-13932 Inappropriate implementation in Sharing in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 5.3 CVE-2026-13933 Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer proce… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13936 Inappropriate implementation in Passwords in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitiv… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13937 Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer proce… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13931 Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer p… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 5.5 CVE-2026-13914 Inappropriate implementation in Passwords in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive inf… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 HIGH 8.8 CVE-2026-13897 Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a… Chrome 150.0.7871.47+ Fix from $1,9502026-06-30 HIGH 8.1 CVE-2026-13864 Insufficient policy enforcement in WebHID in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious ext… Chrome 150.0.7871.47+ Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-13828 Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive informat… Chrome 150.0.7871.46+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13818 Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a c… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 HIGH 7.8 CVE-2026-13800 Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege esc… Chrome 150.0.7871.47+ Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2025-24816 Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could… Mantaray Nm 25R2-NM+ Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-51221 A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a Denial of Service (DoS) via su… Mitigation only Fix from $1,9502026-06-29 MEDIUM 6.5 CVE-2026-43713 A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.… Safari 26.5.2+ Fix from $1,6002026-06-29 HIGH 7.1 CVE-2026-43701 The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, mac… Safari 26.5.2+ Fix from $1,9502026-06-29 HIGH 7.5 CVE-2026-49049EPSS 28% The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON file… Helix3 after 3.1.1 Fix from $1,9502026-06-29 HIGH 7.3 CVE-2026-13568 A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_hand… Mitigation only Fix from $1,9502026-06-29 HIGH 7.3 CVE-2026-13553 A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller… Mitigation only Fix from $1,9502026-06-29 HIGH 7.3 CVE-2026-13547 A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/… Mitigation only Fix from $1,9502026-06-29 MEDIUM 6.3 CVE-2026-13544 A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. Thi… Mitigation only Fix from $1,6002026-06-29 HIGH 7.3 CVE-2026-50132 Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required)… Budibase 3.39.0+ Fix from $1,9502026-06-26 MEDIUM 5.4 CVE-2026-56823 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/… Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.0 CVE-2026-48529 GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCac… Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2026-48928 A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supporte… Node.js Patch available Fix from $1,6002026-06-26 CRITICAL 9.8 CVE-2026-48930 A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolve… Node.js Patch available Fix from $2,3002026-06-26 MEDIUM 6.5 CVE-2026-56050 Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. Thi… No fix yet Fix from $1,6002026-06-25 HIGH 7.8 CVE-2026-46733 Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacke… Display And Peripheral Manager 2.3.0+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-12490 When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no c… Nsd 4.14.3+ Fix from $1,9502026-06-25 HIGH 7.1 CVE-2026-52810 Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service … Patch available Fix from $1,9502026-06-24 MEDIUM 6.5 CVE-2026-31978 motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 ar… Mitigation only Fix from $1,6002026-06-24