Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Unclassified MEDIUM 6.3
CVE-2026-48115

Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.3
CVE-2026-18631

A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/sr…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-18584

A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of …

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.4
CVE-2026-67332

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens fo…

No fix yet
Fix from $1,600 2026-08-01
Mcp Toolbox For Databases HIGH 7.7
CVE-2026-14538

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1…

Fix: after 1.4.0
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.3
CVE-2026-48499

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut…

No fix yet
Fix from $2,300 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-23981

An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboar…

No fix yet
Fix from $1,600 2026-07-30
Calico MEDIUM 6.5
CVE-2026-41187

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy,…

Fix: 3.21.7 / 3.22.4+
Fix from $1,600 2026-07-30
Gridbox MEDIUM 5.3
CVE-2026-66488

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

Fix: 2.20.2+
Fix from $1,600 2026-07-29
Build Of Keycloak MEDIUM 6.5
CVE-2026-18207

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of …

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.1
CVE-2026-47726

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGe…

No fix yet
Fix from $1,950 2026-07-28
Activemq MEDIUM 6.5
CVE-2026-61487

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypas…

Fix: 5.19.9 / 6.2.8+
Fix from $1,600 2026-07-28
Ipados MEDIUM 6.5
CVE-2026-64743

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6,…

Fix: 26.6+
Fix from $1,600 2026-07-27
Ipados MEDIUM 5.5
CVE-2026-64711

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8…

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
Safari MEDIUM 6.5
CVE-2026-43792

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to acce…

Fix: 26.6+
Fix from $1,600 2026-07-27
macOS MEDIUM 5.5
CVE-2026-43775

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be abl…

Fix: 15.7.8 / 26.6+
Fix from $1,600 2026-07-27
macOS MEDIUM 5.5
CVE-2026-43756

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may …

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
Next.js HIGH 8.2
CVE-2026-64642

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applica…

Fix: 16.2.11+
Fix from $1,950 2026-07-27
Unclassified MEDIUM 5.0
CVE-2026-17531

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/route…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.3
CVE-2026-17529

A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The …

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.3
CVE-2026-17530

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.3
CVE-2026-17434

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of t…

No fix yet
Fix from $1,600 2026-07-26
Unclassified MEDIUM 5.3
CVE-2026-17433

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk…

No fix yet
Fix from $1,600 2026-07-26
Azure Portal HIGH 7.5
CVE-2026-62835

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $1,950 2026-07-24
Azure Red Hat Openshift CRITICAL 9.9
CVE-2026-56160

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Work In Process MEDIUM 5.4
CVE-2026-62563

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecte…

Fix: after 12.2.15
Fix from $1,600 2026-07-21
E Business Suite MEDIUM 6.1
CVE-2026-62444

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a…

Fix: after 12.2.15
Fix from $1,600 2026-07-21
Mysql Connectors MEDIUM 6.5
CVE-2026-61082

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily…

No fix yet
Fix from $1,600 2026-07-21
E Business Suite MEDIUM 5.4
CVE-2026-60957

Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that ar…

Fix: after 12.2.15
Fix from $1,600 2026-07-21
Property Manager MEDIUM 5.4
CVE-2026-60911

Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affect…

Fix: after 12.2.15
Fix from $1,600 2026-07-21