Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.6 CVE-2026-40474 wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.ch… Wger 2.5+ Fix from $1,9502026-04-17 MEDIUM 5.3 CVE-2026-40304 zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contai… Zrok 2.0.1+ Fix from $1,6002026-04-17 MEDIUM 5.3 CVE-2026-6492 A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an u… Patch available Fix from $1,6002026-04-17 MEDIUM 6.3 CVE-2026-6489 A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of th… Mitigation only Fix from $1,6002026-04-17 MEDIUM 6.5 CVE-2026-37100 An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2… Mitigation only Fix from $1,6002026-04-16 CRITICAL 9.8 CVE-2026-31843 The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthent… Mitigation only Fix from $2,3002026-04-16 HIGH 7.5 CVE-2026-30994 Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, inclu… Mitigation only Fix from $1,9502026-04-15 MEDIUM 5.5 CVE-2026-33103 Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. Dynamics 365 9.1.44.15+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32214 Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 HIGH 7.8 CVE-2026-27914 Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-26183 Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally. Windows Server 2012 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 MEDIUM 6.8 CVE-2026-22692 October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vul… October 3.7.13 / 4.1.5+ Fix from $1,6002026-04-14 CRITICAL 9.8 CVE-2026-22564 An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized chang… Mitigation only Fix from $2,3002026-04-13 HIGH 7.5 CVE-2026-22566 An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials.
 … Mitigation only Fix from $1,9502026-04-13 MEDIUM 5.4 CVE-2026-6201 A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of th… Mitigation only Fix from $1,6002026-04-13 CRITICAL 9.8 CVE-2026-31282 Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form. An attacker… Mitigation only Fix from $2,3002026-04-13 MEDIUM 6.5 CVE-2026-34860 Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. Harmonyos No fix yet Fix from $1,6002026-04-13 HIGH 8.1 CVE-2026-40252 FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access… Fastgpt 4.14.10.4+ Fix from $1,9502026-04-10 HIGH 7.5 CVE-2026-23782 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API ide… Control M\/managed File Transfer after 9.0.22 Fix from $1,9502026-04-10 HIGH 8.8 CVE-2026-39942 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-cont… Directus 11.17.0+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-5881 Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted… Chrome 147.0.7727.55+ Fix from $1,6002026-04-08 HIGH 8.8 CVE-2026-5863 Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 147.0.7727.55+ Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-34723 Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access th… Zammad 6.5.4+ Fix from $1,9502026-04-08 MEDIUM 5.7 CVE-2026-34248 Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other'… Zammad Mitigation only Fix from $1,6002026-04-08 CRITICAL 9.1 CVE-2026-34045 Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Des… Podman Desktop 1.26.2+ Fix from $2,3002026-04-07 HIGH 7.8 CVE-2026-35533 mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local proje… Mise after 2026.4.5 Fix from $1,9502026-04-07 HIGH 7.5 CVE-2026-39364 Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by se… Vite after 8.0.4 Fix from $1,9502026-04-07 HIGH 7.5 CVE-2025-56015 In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint. Genieacs No fix yet Fix from $1,9502026-04-07 MEDIUM 5.4 CVE-2026-39346 OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed authenticated users to bypass dis… Orangehrm 5.8.1+ Fix from $1,6002026-04-07 CRITICAL 9.1 CVE-2026-39339 ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (… Churchcrm 7.1.0+ Fix from $2,3002026-04-07