Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.3 CVE-2025-69727 An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (index.js and composeUrlImgPho… Mitigation only Fix from $1,6002026-03-16 HIGH 7.3 CVE-2026-4220 A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the fil… Mitigation only Fix from $1,9502026-03-16 HIGH 7.3 CVE-2026-4221 A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage o… Mitigation only Fix from $1,9502026-03-16 HIGH 7.3 CVE-2026-4201 A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of … Mitigation only Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2026-4194 A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-3… Dnr 202l Firmware after 2026-02-05 Fix from $2,3002026-03-16 HIGH 7.3 CVE-2026-4191 A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Pi… Mitigation only Fix from $1,9502026-03-16 HIGH 7.5 CVE-2026-4193 A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetD… Dir 823g Firmware No fix yet Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2026-4180 A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goa… Dir 816 Firmware Mitigation only Fix from $2,3002026-03-16 MEDIUM 6.9 CVE-2026-3111 Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuarios/[ID]/[username]/thumb_AAxA… Mitigation only Fix from $1,6002026-03-16 HIGH 8.7 CVE-2026-3110 Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/administracion/admin_usuarios.cgi?filtro_est… Mitigation only Fix from $1,9502026-03-16 HIGH 7.1 CVE-2026-32720 The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces).… Mitigation only Fix from $1,9502026-03-16 HIGH 7.1 CVE-2026-0977 IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls. Cics Transaction Gateway Mitigation only Fix from $1,9502026-03-16 MEDIUM 6.7 CVE-2026-4105 A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the cla… Mitigation only Fix from $1,6002026-03-13 HIGH 8.2 CVE-2026-32138 NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vul… Mitigation only Fix from $1,9502026-03-12 HIGH 8.8 CVE-2026-21666 A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. Veeam Backup \& Replication 12.3.2.4465+ Fix from $1,9502026-03-12 HIGH 8.8 CVE-2026-21667 A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. Veeam Backup \& Replication 12.3.2.4465+ Fix from $1,9502026-03-12 MEDIUM 6.5 CVE-2026-3934 Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass same origin policy via a … Chrome 146.0.7680.71+ Fix from $1,6002026-03-11 MEDIUM 5.3 CVE-2026-3939 Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a craf… Chrome 146.0.7680.71+ Fix from $1,6002026-03-11 MEDIUM 5.3 CVE-2026-3940 Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a… Chrome 146.0.7680.71+ Fix from $1,6002026-03-11 HIGH 7.5 CVE-2026-3932 Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions… Chrome 146.0.7680.71+ Fix from $1,9502026-03-11 CRITICAL 9.9 CVE-2026-27591 Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS al… Winter 1.0.477 / 1.1.12+ Fix from $2,3002026-03-11 MEDIUM 6.5 CVE-2026-32102 OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution e… Olivetin after 3000.10.2 Fix from $1,6002026-03-11 CRITICAL 9.9 CVE-2025-66956 Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachme… Mitigation only Fix from $2,3002026-03-11 MEDIUM 5.5 CVE-2026-24509 Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A low privileged attacker with l… Alienware Command Center 6.12.24.0+ Fix from $1,6002026-03-11 CRITICAL 9.8 CVE-2026-31874 Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly… Taskosaur Patch available Fix from $2,3002026-03-11 HIGH 7.5 CVE-2026-31872 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protec… Parse Server 8.6.32 / 9.6.0+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2025-68623 In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file during the installation process,… Mitigation only Fix from $1,9502026-03-11 MEDIUM 6.5 CVE-2026-28803 Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner receives an e-mail with instruc… Open Forms 3.3.13 / 3.4.5+ Fix from $1,6002026-03-11 HIGH 7.2 CVE-2026-31834 Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under ce… Umbraco Cms 16.5.1 / 17.2.2+ Fix from $1,9502026-03-10 MEDIUM 5.3 CVE-2026-31815 Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-un… Unicorn 0.67.0+ Fix from $1,6002026-03-10