Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2026-30962 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.6 and 8.6.19, the valida… Parse Server 8.6.19 / 9.5.2+ Fix from $1,6002026-03-10 CRITICAL 10.0 CVE-2026-30966 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Serv… Parse Server 8.6.20 / 9.5.2+ Fix from $2,3002026-03-10 MEDIUM 5.3 CVE-2026-2742 An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.… Vaadin 14.14.1 / 23.6.7+ Fix from $1,6002026-03-10 HIGH 7.8 CVE-2026-25176 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-24290 Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8511 / 10.0.19044.7058+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-23660 Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. Windows Admin Center 2.6.4+ Fix from $1,9502026-03-10 MEDIUM 6.7 CVE-2026-22628 An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system comman… Fortiswitchaxfixed 1.0.2+ Fix from $1,6002026-03-10 HIGH 8.8 CVE-2026-21262 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. Sql Server 2016 13.0.6480.4 / 13.0.7075.5+ Fix from $1,9502026-03-10 HIGH 7.1 CVE-2026-30926 SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note … Siyuan 3.5.10+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2025-62166 FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is … Freshrss 1.28.0+ Fix from $1,9502026-03-09 HIGH 7.5 CVE-2026-30140 An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/Route… W15e Firmware Mitigation only Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3800 A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?… Resort Reservation System No fix yet Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3797 A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile o… Video Surveillance System Firmware Mitigation only Fix from $1,9502026-03-09 HIGH 7.8 CVE-2026-3796 A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library… Qax Internet Control Gateway after 2025-10-22 Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3748 A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/… Bytedesk 1.4.5.1+ Fix from $1,9502026-03-08 HIGH 8.8 CVE-2026-3749 A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/jav… Bytedesk 1.4.5.1+ Fix from $1,9502026-03-08 HIGH 8.8 CVE-2026-30855 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass … Weknora 0.3.2+ Fix from $1,9502026-03-07 MEDIUM 6.5 CVE-2026-30859 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control… Weknora 0.2.12+ Fix from $1,6002026-03-07 HIGH 7.5 CVE-2026-30244 Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sen… Plane 1.2.2+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2025-70363 Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive… Ez Platform after 2.5.32 Fix from $1,9502026-03-06 MEDIUM 5.0 CVE-2026-29060 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privi… Gokapi 2.2.3+ Fix from $1,6002026-03-06 MEDIUM 5.4 CVE-2026-29061 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a privilege escalation vulnerab… Gokapi 2.2.3+ Fix from $1,6002026-03-06 MEDIUM 6.4 CVE-2026-28682 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implement… Gokapi 2.2.3+ Fix from $1,6002026-03-06 MEDIUM 6.5 CVE-2026-25877 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1… Chartbrew 4.8.1+ Fix from $1,6002026-03-06 HIGH 8.1 CVE-2026-29188 File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Pr… Filebrowser 2.61.1+ Fix from $1,9502026-03-05 HIGH 7.1 CVE-2026-29077 Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user … Frappe 14.100.0 / 15.98.0+ Fix from $1,9502026-03-05 HIGH 8.1 CVE-2026-28410 The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the to… Graph Protocol Contracts 3.0.0+ Fix from $1,9502026-03-05 HIGH 8.1 CVE-2025-70614 OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing… Ussd Gateway Mitigation only Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-28790 OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to term… Olivetin 3000.11.0+ Fix from $1,9502026-03-05 MEDIUM 5.3 CVE-2026-27723 OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belongin… Openproject 17.0.5 / 17.1.2+ Fix from $1,6002026-03-05