Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.8 CVE-2026-41092 Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 MEDIUM 6.5 CVE-2026-49938 A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions ma… Fortiportal 7.2.9 / 7.4.8+ Fix from $1,6002026-06-09 MEDIUM 5.2 CVE-2026-41984 UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity. No fix yet Fix from $1,6002026-06-09 MEDIUM 5.1 CVE-2026-41985 UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity. No fix yet Fix from $1,6002026-06-09 MEDIUM 5.3 CVE-2026-41847 Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 throu… Spring Framework 5.3.49+ Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-41006 Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs be… Spring Hateoas 1.5.7 / 2.3.5+ Fix from $1,9502026-06-09 MEDIUM 6.3 CVE-2026-11532 A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function … Mitigation only Fix from $1,6002026-06-08 CRITICAL 9.6 CVE-2026-46441 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis… Flowise 3.1.2+ Fix from $2,3002026-06-08 CRITICAL 9.6 CVE-2026-42861 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis… Flowise 3.1.2+ Fix from $2,3002026-06-08 MEDIUM 5.0 CVE-2026-42862 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis… Flowise 3.1.2+ Fix from $1,6002026-06-08 HIGH 8.1 CVE-2026-42863 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis… Flowise 3.1.2+ Fix from $1,9502026-06-08 HIGH 7.3 CVE-2026-11474 A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown func… Mitigation only Fix from $1,9502026-06-08 MEDIUM 5.4 CVE-2026-11466 A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/ag… Patch available Fix from $1,6002026-06-07 MEDIUM 5.3 CVE-2026-11458 A weakness has been identified in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This issue affects some unknown processing of the… Mitigation only Fix from $1,6002026-06-07 CRITICAL 9.0 CVE-2026-45746 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manage… Termix 2.3.2+ Fix from $2,3002026-06-05 HIGH 7.3 CVE-2026-11344 A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component… Mitigation only Fix from $1,9502026-06-05 MEDIUM 6.3 CVE-2026-11333 A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dc… Mitigation only Fix from $1,6002026-06-05 CRITICAL 9.8 CVE-2026-48907 KEVEPSS 69% A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in … Jce 2.9.99.5+ Fix from $2,3002026-06-05 MEDIUM 6.0 CVE-2026-11326 OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in for… Mitigation only Fix from $1,6002026-06-05 MEDIUM 6.5 CVE-2026-11275 Inappropriate implementation in Page Info in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the render… Chrome 149.0.7827.53+ Fix from $1,6002026-06-05 MEDIUM 6.5 CVE-2026-11258 Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage i… Chrome 149.0.7827.53+ Fix from $1,6002026-06-05 MEDIUM 6.5 CVE-2026-11210 Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access contro… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11204 Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11190 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious ex… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11193 Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11197 Insufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.3 CVE-2026-11187 Inappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafte… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 8.8 CVE-2026-11179 Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass site isolation via a crafted HTML pag… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 MEDIUM 6.5 CVE-2026-11135 Insufficient policy enforcement in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11078 Inappropriate implementation in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04