Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2026-48899 An improper access check allows privilege escalation through the com_users batch task. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-35223 An improper access check allows unauthorized access to com_config webservice endpoints. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 MEDIUM 6.5 CVE-2026-43934 e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized … Patch available Fix from $1,6002026-05-26 HIGH 7.3 CVE-2026-9495 Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently droppe… Patch available Fix from $1,9502026-05-26 HIGH 7.3 CVE-2026-9517 A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/… Mitigation only Fix from $1,9502026-05-26 MEDIUM 6.3 CVE-2026-9445 A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the… Mitigation only Fix from $1,6002026-05-25 HIGH 7.3 CVE-2026-9421 A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the compo… Mitigation only Fix from $1,9502026-05-25 HIGH 8.5 CVE-2026-9489 NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom p… Mitigation only Fix from $1,9502026-05-25 MEDIUM 6.3 CVE-2026-9412 A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Exec… No fix yet Fix from $1,6002026-05-25 MEDIUM 6.3 CVE-2026-9374 A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the c… Mitigation only Fix from $1,6002026-05-24 MEDIUM 5.3 CVE-2026-9352 A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environm… No fix yet Fix from $1,6002026-05-24 MEDIUM 5.3 CVE-2026-9349 A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/… Mitigation only Fix from $1,6002026-05-24 HIGH 7.1 CVE-2026-39968 TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution … Patch available Fix from $1,9502026-05-22 HIGH 7.5 CVE-2022-31231 Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attac… Elastic Cloud Storage 3.5.1.7 / 3.6.2.4+ Fix from $1,9502026-05-22 CRITICAL 10.0 CVE-2026-34908 KEVEPSS 85% A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized ch… Unifi Os Server 5.0.8 / 5.1.12+ Fix from $2,3002026-05-22 MEDIUM 5.3 CVE-2026-8240 Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealin… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 6.5 CVE-2026-2734 In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-… Mlflow 3.10.0+ Fix from $1,6002026-05-21 HIGH 8.6 CVE-2026-39310 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and p… Mitigation only Fix from $1,9502026-05-20 HIGH 8.8 CVE-2026-44926 InfoScale CmdServer before 7.4.2 mishandles access control. Mitigation only Fix from $1,9502026-05-20 HIGH 7.8 CVE-2026-0856 Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access… Mitigation only Fix from $1,9502026-05-20 CRITICAL 10.0 CVE-2026-34234 CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is… Mitigation only Fix from $2,3002026-05-19 HIGH 8.1 CVE-2026-34358 CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multip… Mitigation only Fix from $1,9502026-05-19 MEDIUM 5.1 CVE-2026-34390 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vulnerability where insufficient… Patch available Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-34233 CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints w… Mitigation only Fix from $1,6002026-05-19 HIGH 7.3 CVE-2026-39250 An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfa… Mitigation only Fix from $1,9502026-05-19 MEDIUM 6.5 CVE-2026-37979 A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidentia… Build Of Keycloak 26.4.12+ Fix from $1,6002026-05-19 MEDIUM 5.3 CVE-2026-31388 Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are reco… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 5.3 CVE-2026-32994 The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any auth… Mitigation only Fix from $1,6002026-05-19 CRITICAL 9.1 CVE-2023-24215 Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator cred… Mitigation only Fix from $2,3002026-05-18 MEDIUM 6.5 CVE-2026-8766 A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of t… Kilo Code Cli after 7.0.47 Fix from $1,6002026-05-17