Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.8 CVE-2026-33834 Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2025-43524 An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.… macOS 14.8.7 / 15.7.7+ Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-40300 Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/his… Zulip Server No fix yet Fix from $1,6002026-05-12 HIGH 8.8 CVE-2026-20887 Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged … Mitigation only Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-43652 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user … macOS 26.5+ Fix from $1,9502026-05-11 MEDIUM 5.5 CVE-2026-28993 This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26… Ipados 14.8.7 / 15.7.7+ Fix from $1,6002026-05-11 HIGH 7.5 CVE-2026-28974 This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7,… Ipados 15.7.7 / 26.5+ Fix from $1,9502026-05-11 HIGH 8.8 CVE-2026-28978 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A… macOS 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 MEDIUM 5.5 CVE-2026-28988 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, wat… Ipados 26.5+ Fix from $1,6002026-05-11 HIGH 7.5 CVE-2026-28965 A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.5 and iPadOS 26.5. A user may be able to view restricted content fr… Ipados 26.5+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28930 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user … macOS 26.5+ Fix from $1,9502026-05-11 MEDIUM 6.5 CVE-2026-28922 This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An ap… macOS 14.8.7 / 15.7.7+ Fix from $1,6002026-05-11 CRITICAL 9.9 CVE-2026-7813 Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. M… Pgadmin 4 9.15+ Fix from $2,3002026-05-11 HIGH 7.2 CVE-2025-9973 Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication … Identity Server 7.1.0.26+ Fix from $1,9502026-05-11 CRITICAL 9.4 CVE-2026-42569 phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access… Patch available Fix from $2,3002026-05-09 MEDIUM 6.8 CVE-2026-1749 There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permi… Mitigation only Fix from $1,6002026-05-09 HIGH 8.8 CVE-2026-42205 Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in th… Mitigation only Fix from $1,9502026-05-08 MEDIUM 5.4 CVE-2026-41487 Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is a role-based-access co… Langfuse 3.167.0+ Fix from $1,6002026-05-08 HIGH 8.1 CVE-2026-41491 Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-… Dapr 1.15.14 / 1.16.14+ Fix from $1,9502026-05-08 HIGH 7.8 CVE-2026-8069 PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that use… Nitrosense 3.00.3198 / 3.01.3056+ Fix from $1,9502026-05-08 CRITICAL 9.9 CVE-2025-69691 Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only … Pfsense Mitigation only Fix from $2,3002026-05-08 HIGH 8.8 CVE-2026-42278 UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a crit… Patch available Fix from $1,9502026-05-08 MEDIUM 5.5 CVE-2026-41646 Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScrip… Nuclei 3.8.0+ Fix from $1,6002026-05-08 CRITICAL 10.0 CVE-2026-41900 OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was… Openlearnx Patch available Fix from $2,3002026-05-08 MEDIUM 6.3 CVE-2026-8127 A vulnerability has been found in eladmin up to 2.7. Impacted is the function checkLevel of the file /rest/UserController.java of the component Users… Mitigation only Fix from $1,6002026-05-08 CRITICAL 9.9 CVE-2026-33109 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Azure Managed Instance For Apache Cassandra Mitigation only Fix from $2,3002026-05-07 CRITICAL 10.0 CVE-2026-35435 Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-37709 Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to … Snipe It 8.4.1+ Fix from $2,3002026-05-07 HIGH 8.8 CVE-2026-5786EPSS 6% An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to ga… Endpoint Manager Mobile 12.6.1.1+ Fix from $1,9502026-05-07 CRITICAL 9.8 CVE-2026-5788 An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitra… Endpoint Manager Mobile 12.6.1.1+ Fix from $2,3002026-05-07