Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2026-1061 A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/… Teamwork Management System after 2.28.0 Fix from $2,3002026-01-17 MEDIUM 5.4 CVE-2026-1009 A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An … Altium Live Mitigation only Fix from $1,6002026-01-15 MEDIUM 6.5 CVE-2026-23494 Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side aut… Pimcore 11.5.14 / 12.3.1+ Fix from $1,6002026-01-15 MEDIUM 5.4 CVE-2026-23496 Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper se… Web2print Tools 5.2.2 / 6.1.1+ Fix from $1,6002026-01-15 HIGH 8.8 CVE-2025-61973 A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can repla… Mitigation only Fix from $1,9502026-01-15 HIGH 7.5 CVE-2025-64516 GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any … Glpi 10.0.21 / 11.0.3+ Fix from $1,9502026-01-15 CRITICAL 9.1 CVE-2026-22909 Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potential… Tdc X401gl Firmware Mitigation only Fix from $2,3002026-01-15 HIGH 7.5 CVE-2026-21889 Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access contro… Weblate 5.15.2+ Fix from $1,9502026-01-14 HIGH 8.5 CVE-2025-14338 Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v0.69.0 can lead to the same i… Mitigation only Fix from $1,9502026-01-14 MEDIUM 5.3 CVE-2025-68949 n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string … N8n 2.2.0+ Fix from $1,6002026-01-13 HIGH 7.8 CVE-2026-20949 Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. 365 Apps No fix yet Fix from $1,9502026-01-13 HIGH 7.5 CVE-2026-20929 Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 MEDIUM 5.5 CVE-2026-20839 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 HIGH 7.8 CVE-2026-20843 Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.5 CVE-2026-0386 Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. Windows Server 2008 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 CRITICAL 10.0 CVE-2026-0881 Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. Firefox 147.0+ Fix from $2,3002026-01-13 MEDIUM 5.4 CVE-2026-22033 Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability e… Label Studio after 1.22.0 Fix from $1,6002026-01-12 CRITICAL 9.8 CVE-2025-15503 A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function o… Operation And Maintenance Security Management System after 3.0.8 Fix from $2,3002026-01-10 MEDIUM 5.5 CVE-2025-46297 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files… macOS 26.2+ Fix from $1,6002026-01-09 HIGH 7.2 CVE-2025-15495 A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite.php. The manipulation of the… Simple Php Cms No fix yet Fix from $1,9502026-01-09 HIGH 8.4 CVE-2025-68716 KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with … Ks Wr3600 Firmware Mitigation only Fix from $1,9502026-01-08 CRITICAL 9.8 CVE-2026-22043 RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in… Rustfs Mitigation only Fix from $2,3002026-01-08 HIGH 8.1 CVE-2026-21694 Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other u… Titra 0.99.50+ Fix from $1,9502026-01-08 MEDIUM 5.9 CVE-2025-69220 LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file co… Librechat Patch available Fix from $1,6002026-01-07 CRITICAL 9.8 CVE-2026-0643 A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=re… House Rental And Property Listing Project Mitigation only Fix from $2,3002026-01-07 MEDIUM 6.4 CVE-2025-0980 Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. When exploited, an invalid val… Mitigation only Fix from $1,6002026-01-07 MEDIUM 6.5 CVE-2026-21635 An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a… Unifi Connect Ev Station Lite Firmware 1.6.1+ Fix from $1,6002026-01-05 CRITICAL 9.8 CVE-2025-15448 A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the function Upload of the file src/m… Javamall Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2026-0577 A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file … Online Product Reservation System Mitigation only Fix from $2,3002026-01-04 HIGH 7.1 CVE-2026-21447 Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer orde… Bagisto 2.3.10+ Fix from $1,9502026-01-02