Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.1 CVE-2026-48610 Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certai… Mitigation only Fix from $1,9502026-06-12 HIGH 7.2 CVE-2026-47366 Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated admini… Mitigation only Fix from $1,9502026-06-12 HIGH 8.1 CVE-2026-44249 Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15… Netty 4.1.135 / 4.2.15+ Fix from $1,9502026-06-11 HIGH 8.1 CVE-2026-45178 Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticate… Idira Secrets Manager 13.8.1 / 14.2.6+ Fix from $1,9502026-06-11 CRITICAL 9.1 CVE-2026-45177 Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauth… Idira Secrets Manager Edge 1.8+ Fix from $2,3002026-06-11 MEDIUM 5.3 CVE-2025-46308 An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may … Ipados 15.4 / 18.4+ Fix from $1,6002026-06-11 HIGH 7.5 CVE-2025-46315 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user … macOS 26.1+ Fix from $1,9502026-06-11 MEDIUM 5.5 CVE-2025-43339 An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access se… macOS 26.1+ Fix from $1,6002026-06-11 MEDIUM 5.5 CVE-2025-24165 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.… macOS 13.7.5 / 14.7.5+ Fix from $1,6002026-06-11 HIGH 7.5 CVE-2026-41856 The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarch… Spring For Graphql 1.0.7 / 1.3.9+ Fix from $1,9502026-06-11 CRITICAL 10.0 CVE-2026-46695 Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted … Patch available Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-50545 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-50563 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-50564 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 HIGH 7.7 CVE-2026-49822 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 HIGH 7.7 CVE-2026-49823 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 HIGH 8.5 CVE-2026-49824 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 CRITICAL 9.8 CVE-2026-46614 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 MEDIUM 5.5 CVE-2026-20259 In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23… Splunk 9.3.2411.131 / 10.0.7+ Fix from $1,6002026-06-10 HIGH 7.5 CVE-2026-41728 Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when … Spring Data Rest 3.7.20 / 4.3.17+ Fix from $1,9502026-06-10 MEDIUM 5.3 CVE-2026-41837 Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson cu… Spring Data Rest 3.7.20 / 4.3.17+ Fix from $1,6002026-06-10 HIGH 8.6 CVE-2026-47907 Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution … Dreamweaver 21.8+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-39169 SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php. Mitigation only Fix from $1,9502026-06-09 HIGH 8.1 CVE-2026-36720 Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type. Mitigation only Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-49161 Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-06-09 HIGH 7.9 CVE-2026-48578 Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 MEDIUM 6.8 CVE-2026-45658 Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,6002026-06-09 HIGH 7.1 CVE-2026-45649 Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. Excel No fix yet Fix from $1,9502026-06-09 HIGH 7.9 CVE-2026-45654 Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Windows 11 24h2 10.0.26100.8655 / 10.0.26100.32995+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-42829 Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. Windows 11 24h2 10.0.26100.8655 / 10.0.26200.8655+ Fix from $1,9502026-06-09