Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.1 CVE-2026-26417 A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated … Cognix Platform Mitigation only Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-26418 Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access appli… Cognix Platform Mitigation only Fix from $1,9502026-03-05 CRITICAL 9.8 CVE-2026-25702 A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via… Linux Enterprise Server Mitigation only Fix from $2,3002026-03-05 HIGH 8.8 CVE-2026-3541 Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a … Chrome 145.0.7632.159 / 145.0.7632.160+ Fix from $1,9502026-03-04 HIGH 8.8 CVE-2026-3542 Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access… Chrome 145.0.7632.159 / 145.0.7632.160+ Fix from $1,9502026-03-04 HIGH 8.8 CVE-2026-3543 Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory acc… Chrome 145.0.7632.159 / 145.0.7632.160+ Fix from $1,9502026-03-04 MEDIUM 5.8 CVE-2026-20073 A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could all… Adaptive Security Appliance Software Mitigation only Fix from $1,6002026-03-04 MEDIUM 5.8 CVE-2026-20007 A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticat… Secure Firewall Threat Defense Mitigation only Fix from $1,6002026-03-04 MEDIUM 6.5 CVE-2024-55025 Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI sy… Easyweb Mitigation only Fix from $1,6002026-03-03 HIGH 7.5 CVE-2024-55019 Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated att… Easyweb Mitigation only Fix from $1,9502026-03-03 MEDIUM 6.2 CVE-2026-0012 In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to… Android Mitigation only Fix from $1,6002026-03-02 HIGH 8.4 CVE-2025-48619 In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate files due to a logic error in the… Android Mitigation only Fix from $1,9502026-03-02 MEDIUM 6.3 CVE-2025-15597 A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of t… Sqlbot 1.5.0+ Fix from $1,6002026-03-02 HIGH 7.5 CVE-2026-28276 Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded… Initiative 0.32.2+ Fix from $1,9502026-02-26 MEDIUM 6.3 CVE-2026-28230 SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger sends a StopTransaction message… Steve after 3.11.0 Fix from $1,6002026-02-26 CRITICAL 9.1 CVE-2026-28215 hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructur… Hoppscotch 2026.2.0+ Fix from $2,3002026-02-26 MEDIUM 5.4 CVE-2026-28218 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugi… Discourse 2025.12.2 / 2026.1.1+ Fix from $1,6002026-02-26 HIGH 7.5 CVE-2026-27449 Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where c… Mitigation only Fix from $1,9502026-02-26 MEDIUM 5.3 CVE-2026-2356 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Obj… Mitigation only Fix from $1,6002026-02-26 CRITICAL 9.8 CVE-2026-27975 Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbit… Ajenti 2.2.13+ Fix from $2,3002026-02-26 MEDIUM 6.3 CVE-2026-3209 A vulnerability has been found in fosrl Pangolin up to 1.15.4-s.3. This affects the function verifyRoleAccess/verifyApiKeyRoleAccess of the component… Patch available Fix from $1,6002026-02-25 CRITICAL 9.8 CVE-2026-3187 A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api… Sz Boot Parent after 0.9.0 Fix from $2,3002026-02-25 MEDIUM 6.5 CVE-2026-27624 Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denie… Coturn 4.9.0+ Fix from $1,6002026-02-25 MEDIUM 6.5 CVE-2026-24896 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Cont… Openemr 8.0.0+ Fix from $1,6002026-02-25 HIGH 8.8 CVE-2025-63409 Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settin… Gcom Epon 1ge Firmware Mitigation only Fix from $1,9502026-02-24 CRITICAL 10.0 CVE-2026-2768 Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird … Firefox 140.8.0 / 148.0+ Fix from $2,3002026-02-24 HIGH 7.8 CVE-2026-25966 ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule i… Imagemagick 6.9.13-40 / 7.1.2-15+ Fix from $1,9502026-02-24 CRITICAL 9.8 CVE-2026-3025 A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of th… Smart Heating Integrated Management Platform Mitigation only Fix from $2,3002026-02-23 CRITICAL 9.8 CVE-2026-2983 A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin… Student Result Management System Mitigation only Fix from $2,3002026-02-23 HIGH 8.8 CVE-2026-2979 A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/modu… Fastapiadmin after 2.2.0 Fix from $1,9502026-02-23