Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2026-64952 The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned … No fix yet Fix from $4,0002026-08-12 HIGH 7.1 CVE-2026-63177 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evalu… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.3 CVE-2026-73221 CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use… No fix yet Fix from $4,0002026-08-11 HIGH 8.1 CVE-2026-18712 An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collectio… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-18698 An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-18696 An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definiti… No fix yet Fix from $4,0002026-08-11 HIGH 8.1 CVE-2026-18690 An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.3 CVE-2026-73090 PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Upd… No fix yet Fix from $5,7502026-08-11 MEDIUM 5.8 CVE-2026-73213 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-… No fix yet Fix from $4,0002026-08-11 CRITICAL 10.0 CVE-2026-71398 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of … No fix yet Fix from $5,7502026-08-11 CRITICAL 9.1 CVE-2026-71362 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul… No fix yet Fix from $5,7502026-08-11 HIGH 7.7 CVE-2026-48447 Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current… Lightroom 15.5+ Fix from $4,9002026-08-11 HIGH 7.6 CVE-2026-48415 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker coul… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-48416 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-48411 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileg… No fix yet Fix from $4,0002026-08-11 CRITICAL 10.0 CVE-2026-27302 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of … No fix yet Fix from $5,7502026-08-11 HIGH 7.3 CVE-2026-71383 is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.6 CVE-2026-71384 is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability… No fix yet Fix from $5,7502026-08-11 HIGH 8.8 CVE-2026-71387 ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. … No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-69278 Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Visual Studio Code 1.132.1+ Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-63512 Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-62872 Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. .net Framework No fix yet Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-62775 Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. Windows 11 26h1 10.0.28000.2704+ Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-61925 Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-48375 ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker c… Coldfusion No fix yet Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-25652 is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulne… Coldfusion No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-72921 SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.… No fix yet Fix from $4,9002026-08-11 HIGH 7.2 CVE-2026-18635 Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, t… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-72771 n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoin… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.2 CVE-2026-13737 CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance … No fix yet Fix from $5,7502026-08-11