Vulnerability index

Browse CVEs

5,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2021-32084 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or… Kace Systems Management Appliance No fix yet Fix from $2,3002026-07-27 HIGH 8.2 CVE-2026-64737 An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26… macOS 14.8.8 / 15.7.8+ Fix from $1,9502026-07-27 CRITICAL 9.8 CVE-2026-64738 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS So… macOS 14.8.8 / 15.7.8+ Fix from $2,3002026-07-27 MEDIUM 5.5 CVE-2026-64723 A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, m… macOS 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 CRITICAL 9.8 CVE-2026-64702 An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.… macOS 14.8.8 / 15.7.8+ Fix from $2,3002026-07-27 MEDIUM 6.5 CVE-2026-43821 An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPa… Safari 26.6+ Fix from $1,6002026-07-27 MEDIUM 5.5 CVE-2026-43819 An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive u… macOS 26.6+ Fix from $1,6002026-07-27 CRITICAL 9.8 CVE-2026-43779 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app ma… macOS 14.8.8 / 15.7.8+ Fix from $2,3002026-07-27 HIGH 8.6 CVE-2026-43760 An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to … macOS 14.8.8 / 26.6+ Fix from $1,9502026-07-27 MEDIUM 5.5 CVE-2026-43763 A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6… macOS 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 HIGH 7.1 CVE-2026-28945 A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe… macOS 14.8.8 / 15.7.8+ Fix from $1,9502026-07-27 HIGH 7.7 CVE-2026-12990 An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run witho… No fix yet Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-14235 The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, maki… No fix yet Fix from $1,9502026-07-27 MEDIUM 5.0 CVE-2026-17432 A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-age… No fix yet Fix from $1,6002026-07-26 HIGH 8.5 CVE-2026-48034 Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there … No fix yet Fix from $1,9502026-07-24 CRITICAL 9.8 CVE-2026-58630 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. Azure App Service For Linux No fix yet Fix from $2,3002026-07-24 HIGH 7.1 CVE-2026-9765 Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can acce… No fix yet Fix from $1,9502026-07-24 CRITICAL 9.8 CVE-2026-15704 In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by incon… No fix yet Fix from $2,3002026-07-24 MEDIUM 5.1 CVE-2026-12702 In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment. No fix yet Fix from $1,6002026-07-24 HIGH 7.5 CVE-2026-14603 The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated us… No fix yet Fix from $1,9502026-07-24 MEDIUM 6.5 CVE-2026-12688 The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthentic… No fix yet Fix from $1,6002026-07-24 HIGH 7.2 CVE-2026-35425 Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. Azure Api Management No fix yet Fix from $1,9502026-07-24 HIGH 8.7 CVE-2026-65759 Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment informatio… No fix yet Fix from $1,9502026-07-23 CRITICAL 9.2 CVE-2026-65760 Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access ch… No fix yet Fix from $2,3002026-07-23 HIGH 8.1 CVE-2026-65757 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose … No fix yet Fix from $1,9502026-07-23 HIGH 8.2 CVE-2026-65758 Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access… No fix yet Fix from $1,9502026-07-23 HIGH 8.8 CVE-2026-64876 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consiste… No fix yet Fix from $1,9502026-07-23 MEDIUM 5.4 CVE-2026-64871 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not … No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2024-58330 A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event d… No fix yet Fix from $1,9502026-07-23 CRITICAL 9.9 CVE-2026-60369 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22