Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2026-31272 MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks pro… Mrcms Mitigation only Fix from $2,3002026-04-07 HIGH 7.2 CVE-2026-1078 An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running autom… Mitigation only Fix from $1,9502026-04-07 MEDIUM 6.0 CVE-2026-1079 A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Peg… Mitigation only Fix from $1,6002026-04-07 CRITICAL 9.8 CVE-2026-1114 In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key f… Lollms Patch available Fix from $2,3002026-04-07 HIGH 7.5 CVE-2026-35185 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes … Haxiam No fix yet Fix from $1,9502026-04-06 HIGH 7.5 CVE-2026-35172 Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after a… Distribution 3.1.0+ Fix from $1,9502026-04-06 MEDIUM 6.3 CVE-2026-5670 A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This issue affects the function move… Mitigation only Fix from $1,6002026-04-06 CRITICAL 10.0 CVE-2026-34444 Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are acc… Lupa after 2.6 Fix from $2,3002026-04-06 MEDIUM 5.3 CVE-2026-5601 A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of the file /bin.rar of the comp… Mitigation only Fix from $1,6002026-04-05 HIGH 7.5 CVE-2026-5585 A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/websocket/task_manager.go of … Ai Infra Guard No fix yet Fix from $1,9502026-04-05 CRITICAL 9.8 CVE-2026-5573 A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipul… Hi Led Wr120 G2 Firmware Mitigation only Fix from $2,3002026-04-05 HIGH 7.5 CVE-2026-5571 A vulnerability was identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The impacted element is an unknown function of the file /fs of the co… Hi Led Wr120 G2 Firmware No fix yet Fix from $1,9502026-04-05 CRITICAL 9.8 CVE-2026-5569 A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the componen… Hi Led Wr120 G2 Firmware Mitigation only Fix from $2,3002026-04-05 MEDIUM 6.3 CVE-2026-5546 A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/mode… Mitigation only Fix from $1,6002026-04-05 CRITICAL 9.8 CVE-2026-5526 A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionali… 4g03 Pro Firmware Mitigation only Fix from $2,3002026-04-04 CRITICAL 9.8 CVE-2026-35616 KEVEPSS 91% A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized … Forticlientems Patch available Fix from $2,3002026-04-04 CRITICAL 9.1 CVE-2021-4477 Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connecti… Mitigation only Fix from $2,3002026-04-03 MEDIUM 5.4 CVE-2017-20233 Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and… Mitigation only Fix from $1,6002026-04-03 MEDIUM 5.3 CVE-2026-5484 A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormat… Patch available Fix from $1,6002026-04-03 MEDIUM 6.3 CVE-2026-5472 A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unkn… No fix yet Fix from $1,6002026-04-03 HIGH 7.5 CVE-2024-44303 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify protected part… macOS 15.1+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2024-44219 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious application with root privileg… macOS 15.1+ Fix from $1,9502026-04-02 HIGH 7.1 CVE-2024-40858 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access Contacts with… macOS 15.1+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-33951 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthent… Signal K Server 2.24.0+ Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2026-2699EPSS 58% Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to … Sharefile Storage Zones Controller 5.12.4+ Fix from $2,3002026-04-02 MEDIUM 6.5 CVE-2026-5330 A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the … Mitigation only Fix from $1,6002026-04-02 HIGH 8.8 CVE-2026-34572 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $1,9502026-04-01 HIGH 8.8 CVE-2026-34570 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $1,9502026-04-01 MEDIUM 5.3 CVE-2026-5312 A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS… Dns 1550 04 Firmware after 2026-02-05 Fix from $1,6002026-04-01 MEDIUM 5.3 CVE-2026-5311 A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326… Dnr 202l Firmware after 2026-02-05 Fix from $1,6002026-04-01