Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 6.5
CVE-2026-64952

The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned …

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.1
CVE-2026-63177

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evalu…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73221

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.1
CVE-2026-18712

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collectio…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-18698

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-18696

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definiti…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.1
CVE-2026-18690

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.3
CVE-2026-73090

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Upd…

No fix yet
Fix from $5,750 2026-08-11
Unclassified MEDIUM 5.8
CVE-2026-73213

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-…

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-71398

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-71362

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…

No fix yet
Fix from $5,750 2026-08-11
Lightroom HIGH 7.7
CVE-2026-48447

Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current…

Fix: 15.5+
Fix from $4,900 2026-08-11
Unclassified HIGH 7.6
CVE-2026-48415

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker coul…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-48416

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-48411

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileg…

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-27302

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.3
CVE-2026-71383

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.6
CVE-2026-71384

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.8
CVE-2026-71387

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. …

No fix yet
Fix from $4,900 2026-08-11
Visual Studio Code HIGH 7.8
CVE-2026-69278

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Fix: 1.132.1+
Fix from $4,900 2026-08-11
Sharepoint Server MEDIUM 6.5
CVE-2026-63512

Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
.net Framework HIGH 8.8
CVE-2026-62872

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $4,900 2026-08-11
Windows 11 26h1 MEDIUM 5.5
CVE-2026-62775

Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

Fix: 10.0.28000.2704+
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61925

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Coldfusion MEDIUM 6.5
CVE-2026-48375

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker c…

No fix yet
Fix from $4,000 2026-08-11
Coldfusion HIGH 7.8
CVE-2026-25652

is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulne…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-72921

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.2
CVE-2026-18635

Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, t…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72771

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoin…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.2
CVE-2026-13737

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance …

No fix yet
Fix from $5,750 2026-08-11