Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2026-11026 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious ex… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11017 Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proce… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 5.3 CVE-2024-27891 On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for pack… Mitigation only Fix from $1,6002026-06-04 HIGH 8.8 CVE-2026-5228 Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly C… Mitigation only Fix from $1,9502026-06-04 CRITICAL 9.8 CVE-2026-35904 Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauth… Mitigation only Fix from $2,3002026-06-04 MEDIUM 6.3 CVE-2026-10806 A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.ph… Mitigation only Fix from $1,6002026-06-04 MEDIUM 6.3 CVE-2026-10807 A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/chang… Mitigation only Fix from $1,6002026-06-04 CRITICAL 9.8 CVE-2026-42074 OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableS… Openclaude 0.5.1+ Fix from $2,3002026-06-02 MEDIUM 6.1 CVE-2026-40713 Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical … Thinos 2602_10.0765+ Fix from $1,6002026-06-02 HIGH 7.8 CVE-2026-40715 Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local acces… Thinos 2602_10.0765+ Fix from $1,9502026-06-02 MEDIUM 5.4 CVE-2026-9522 Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without adminis… Devolutions Server 2026.1.20.0+ Fix from $1,6002026-06-02 MEDIUM 5.3 CVE-2026-9590 Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry ed… Devolutions Server 2026.1.20.0+ Fix from $1,6002026-06-02 MEDIUM 6.9 CVE-2026-45080 Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of pa… Mitigation only Fix from $1,6002026-06-02 CRITICAL 9.8 CVE-2026-7198 CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access… Sitefinity 15.4.8630+ Fix from $2,3002026-06-02 MEDIUM 6.5 CVE-2026-3198 MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically,… Mlflow No fix yet Fix from $1,6002026-06-02 HIGH 7.8 CVE-2025-22426 In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to lo… Android Mitigation only Fix from $1,9502026-06-01 HIGH 8.8 CVE-2026-9614 An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administra… Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-45282 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a… Nextcloud Server 27.1.11.5 / 28.0.14.17+ Fix from $1,6002026-06-01 HIGH 8.8 CVE-2026-45284 Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where pr… User Oidc 8.4.0+ Fix from $1,9502026-06-01 HIGH 7.5 CVE-2026-37235 FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The validation function valid_… Flexric No fix yet Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10277 A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of … Patch available Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-45157 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, w… Patch available Fix from $1,6002026-06-01 MEDIUM 5.3 CVE-2026-10255 A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_stateme… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-10205 A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systpa… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-10172 A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file ap… Mitigation only Fix from $1,6002026-05-31 MEDIUM 6.3 CVE-2026-10152 A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/gith… Mitigation only Fix from $1,6002026-05-30 HIGH 8.1 CVE-2026-45707 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI… N8n Mcp 2.51.2+ Fix from $1,9502026-05-29 CRITICAL 9.3 CVE-2026-45043 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoi… Mitigation only Fix from $2,3002026-05-29 MEDIUM 5.3 CVE-2026-46842 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerabili… Rest Data Services after 26.1.0 Fix from $1,6002026-05-28 CRITICAL 9.9 CVE-2026-46839 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerabili… Rest Data Services after 26.1.0 Fix from $2,3002026-05-28