Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.9 CVE-2026-35281 Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are… Webcenter Enterprise Capture Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-35282 Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are… Webcenter Enterprise Capture Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-35283 Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are… Webcenter Enterprise Capture Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-35284 Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are… Webcenter Enterprise Capture Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-35285 Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are… Webcenter Enterprise Capture Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-35268 Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and… Identity Manager Mitigation only Fix from $2,3002026-06-17 HIGH 7.5 CVE-2026-35269 Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12… Identity Manager Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.1 CVE-2026-35270 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content Mitigation only Fix from $2,3002026-06-17 HIGH 8.7 CVE-2026-35271 Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected a… Peoplesoft Enterprise Pt Peopletools Mitigation only Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-35275 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Shared Folders). The supported version that is affected is 7… Vm Virtualbox Mitigation only Fix from $1,9502026-06-17 HIGH 8.3 CVE-2026-35262 Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are … Data Integrator Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.9 CVE-2026-35263 Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.2.0.0 and … Weblogic Server Mitigation only Fix from $2,3002026-06-17 HIGH 7.5 CVE-2026-47261 Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and FileP… Wasmtime 24.0.9 / 36.0.10+ Fix from $1,9502026-06-15 HIGH 8.1 CVE-2026-50891 Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request. Mitigation only Fix from $1,9502026-06-15 MEDIUM 6.5 CVE-2026-50892 Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain… Mitigation only Fix from $1,6002026-06-15 HIGH 8.1 CVE-2026-50881 Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator an… Mitigation only Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-50884 Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components. Mitigation only Fix from $1,9502026-06-15 HIGH 7.5 CVE-2026-50885 Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints v… Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.1 CVE-2026-50886 Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted … Mitigation only Fix from $2,3002026-06-15 HIGH 8.1 CVE-2026-50875 Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or del… Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.8 CVE-2026-39006 An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component. Mitigation only Fix from $2,3002026-06-15 MEDIUM 6.8 CVE-2026-36933 An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature. Mitigation only Fix from $1,6002026-06-15 HIGH 7.1 CVE-2026-5230 Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Con… Mitigation only Fix from $1,9502026-06-15 MEDIUM 5.3 CVE-2026-12203 A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/a… Patch available Fix from $1,6002026-06-15 MEDIUM 6.5 CVE-2026-53520 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, authenti… Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.4 CVE-2026-44783 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l… Discourse 2026.1.0 / 2026.1.4+ Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-47182 Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path… Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-44976 Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue h… Mitigation only Fix from $1,6002026-06-12 MEDIUM 6.9 CVE-2026-44208 Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint a… Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-47200 Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nit… Nuxt 3.21.6 / 4.4.6+ Fix from $1,6002026-06-12