Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.1 CVE-2026-27708 FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method ac… Mitigation only Fix from $1,9502026-06-24 HIGH 7.1 CVE-2026-56257 Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() workflow and creating split-bra… Mitigation only Fix from $1,9502026-06-24 MEDIUM 6.5 CVE-2026-56302 Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, insert… Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.9 CVE-2026-47279 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied c… Mitigation only Fix from $1,6002026-06-23 HIGH 7.1 CVE-2026-54761 Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway… Traefik 3.6.21 / 3.7.5+ Fix from $1,9502026-06-23 HIGH 8.3 CVE-2026-54010 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated u… Open Webui 0.9.6+ Fix from $1,9502026-06-23 HIGH 7.1 CVE-2026-54012 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can cre… Open Webui 0.9.6+ Fix from $1,9502026-06-23 MEDIUM 6.4 CVE-2026-54015 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI's prompt version-histor… Open Webui 0.9.6+ Fix from $1,6002026-06-23 HIGH 7.5 CVE-2026-52844 Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outsid… Caddy 2.11.4+ Fix from $1,9502026-06-23 MEDIUM 6.5 CVE-2026-49411 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked the permission against the orig… Deno 2.8.0+ Fix from $1,6002026-06-23 CRITICAL 9.9 CVE-2026-54305 n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature… N8n 1.123.55 / 2.25.7+ Fix from $2,3002026-06-23 MEDIUM 5.4 CVE-2026-44958 An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such perm… Mitigation only Fix from $1,6002026-06-23 HIGH 8.1 CVE-2026-28381 The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files… Snowflake after 1.14.12 Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-56253 Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allows unauthenticated attack… Mitigation only Fix from $1,9502026-06-21 HIGH 7.8 CVE-2026-12786 A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown functionality in the library… Mitigation only Fix from $1,9502026-06-21 HIGH 7.8 CVE-2026-12782 A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of… Mitigation only Fix from $1,9502026-06-21 HIGH 7.8 CVE-2026-12784 A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the compon… Mitigation only Fix from $1,9502026-06-21 HIGH 7.8 CVE-2026-12781 A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the … Mitigation only Fix from $1,9502026-06-21 HIGH 7.8 CVE-2026-12778 A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the c… Mitigation only Fix from $1,9502026-06-21 HIGH 7.8 CVE-2026-12779 A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the co… Mitigation only Fix from $1,9502026-06-21 HIGH 7.8 CVE-2026-12780 A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Dr… Mitigation only Fix from $1,9502026-06-21 HIGH 7.5 CVE-2026-56082 Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_b… Mitigation only Fix from $1,9502026-06-19 HIGH 8.7 CVE-2026-4026 A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account… Mitigation only Fix from $1,9502026-06-19 HIGH 7.1 CVE-2026-4027 A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized access to attachment files due to … Mitigation only Fix from $1,9502026-06-19 HIGH 7.8 CVE-2026-46461 Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with local access… Server Hardware Manager 3.2.2+ Fix from $1,9502026-06-19 CRITICAL 9.9 CVE-2026-47647 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. Dynamics 365 Mitigation only Fix from $2,3002026-06-18 HIGH 7.6 CVE-2026-46699 conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to v… Patch available Fix from $1,9502026-06-18 HIGH 8.2 CVE-2026-48617 A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality … Node.js after 26.3.0 Fix from $1,9502026-06-18 MEDIUM 6.9 CVE-2026-54533 vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other … Mitigation only Fix from $1,6002026-06-17 HIGH 7.3 CVE-2026-12529 A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown fu… Mitigation only Fix from $1,9502026-06-17