Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.7 CVE-2025-61879 In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism. Nios after 8.6.5 Fix from $1,9502026-02-12 CRITICAL 9.0 CVE-2025-69634 Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.… Mitigation only Fix from $2,3002026-02-12 HIGH 7.8 CVE-2026-23856 Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, con… Mitigation only Fix from $1,9502026-02-12 HIGH 7.1 CVE-2026-20628 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS … Ipados 14.8.4 / 15.7.4+ Fix from $1,9502026-02-11 MEDIUM 5.5 CVE-2026-20638 A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3. A user with Live Caller ID app extensions turned o… Ipados 26.3+ Fix from $1,6002026-02-11 HIGH 7.5 CVE-2026-2250 The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQ… Mitigation only Fix from $1,9502026-02-11 CRITICAL 9.8 CVE-2025-8025 Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Func… Mitigation only Fix from $2,3002026-02-11 MEDIUM 6.9 CVE-2025-29939 Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secu… Mitigation only Fix from $1,6002026-02-10 HIGH 8.8 CVE-2026-21255 Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21238 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-0653 On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchr… Tapo C260 Firmware 1.1.9+ Fix from $1,6002026-02-10 HIGH 7.5 CVE-2026-25231 FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerabil… Filerise 3.3.0+ Fix from $1,9502026-02-09 HIGH 7.2 CVE-2026-2226 A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File … Douphp after 1.9 Fix from $1,9502026-02-09 HIGH 7.2 CVE-2026-2213 A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Adminis… Online Music Site No fix yet Fix from $1,9502026-02-09 CRITICAL 9.8 CVE-2026-2183 A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This aff… Certificate after 2017-10-16 Fix from $2,3002026-02-08 CRITICAL 9.8 CVE-2026-2164 A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/pr… E Commerce Mitigation only Fix from $2,3002026-02-08 HIGH 7.5 CVE-2026-2148 A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-bin/DownloadFlash of the compo… Ac21 Firmware No fix yet Fix from $1,9502026-02-08 MEDIUM 5.3 CVE-2026-2147 A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Mana… Ac21 Firmware No fix yet Fix from $1,6002026-02-08 HIGH 8.8 CVE-2026-2146 A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar… Yshopmall after 1.9.1 Fix from $1,9502026-02-08 CRITICAL 9.8 CVE-2026-2133 A weakness has been identified in code-projects Online Music Site 1.0. Impacted is an unknown function of the file /Administrator/PHP/AdminUpdateCate… Online Music Site Mitigation only Fix from $2,3002026-02-08 HIGH 8.8 CVE-2026-2206 A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of t… Wekan 8.21+ Fix from $1,9502026-02-08 MEDIUM 5.3 CVE-2026-2207 A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the c… Wekan 8.21+ Fix from $1,6002026-02-08 HIGH 8.8 CVE-2026-2075 A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected is the function saveRolePermission o… Warehouse after 2025-10-06 Fix from $1,9502026-02-07 HIGH 7.5 CVE-2026-25758 Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow th… Spree 4.10.3 / 5.0.8+ Fix from $1,9502026-02-06 HIGH 7.5 CVE-2026-2056 A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /… Dir 605l Firmware No fix yet Fix from $1,9502026-02-06 HIGH 7.5 CVE-2026-2054 A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Ha… Dir 605l Firmware No fix yet Fix from $1,9502026-02-06 HIGH 7.5 CVE-2026-2055 A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Cli… Dir 605l Firmware No fix yet Fix from $1,9502026-02-06 MEDIUM 6.5 CVE-2026-2009 A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/… Gas Agency Management System No fix yet Fix from $1,6002026-02-06 CRITICAL 9.8 CVE-2026-24300 Azure Front Door Elevation of Privilege Vulnerability Azure Front Door No fix yet Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-24302 Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. Azure Arc Mitigation only Fix from $2,3002026-02-05