Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Edge Chromium HIGH 8.3
CVE-2026-58284

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium CRITICAL 10.0
CVE-2026-57983

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Fix: 150.0.4078.48+
Fix from $2,300 2026-07-03
Unclassified HIGH 7.6
CVE-2026-50279

Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, theEntriesController::actionSaveEntry() performs ent…

Patch available
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-56320

Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_id parameter without validatin…

Mitigation only
Fix from $1,950 2026-06-30
N8n HIGH 7.7
CVE-2026-56350

n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attacke…

Fix: 2.8.0+
Fix from $1,950 2026-06-30
Unclassified HIGH 7.6
CVE-2026-56249

Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authenticated users to overwrite ex…

Mitigation only
Fix from $1,950 2026-06-30
Langflow CRITICAL 9.8
CVE-2026-7663

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t…

Fix: 1.10.0+
Fix from $2,300 2026-06-30
Fastify\/express CRITICAL 9.1
CVE-2026-6556

@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string …

Fix: 4.0.7+
Fix from $2,300 2026-06-30
Activemq HIGH 8.1
CVE-2026-49877

Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Tomcat MEDIUM 6.5
CVE-2026-55956

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method o…

Fix: 9.0.119 / 10.1.56+
Fix from $1,600 2026-06-29
Unclassified MEDIUM 5.0
CVE-2026-13591

A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/managers/ChannelBridge.ts of …

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 5.4
CVE-2026-13549

A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file appli…

Mitigation only
Fix from $1,600 2026-06-29
Unclassified MEDIUM 5.0
CVE-2026-13534

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryServi…

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 5.6
CVE-2026-13524

A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/servic…

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.3
CVE-2026-13512

A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/ser…

Patch available
Fix from $1,600 2026-06-28
Unclassified MEDIUM 5.5
CVE-2026-13508

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component…

Patch available
Fix from $1,600 2026-06-28
Unclassified MEDIUM 6.7
CVE-2026-49278

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.1…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.6
CVE-2026-56231

Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.8
CVE-2026-46552

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the same base-member capabilities as…

Mitigation only
Fix from $1,600 2026-06-23
Open Webui HIGH 7.1
CVE-2026-54012

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can cre…

Fix: 0.9.6+
Fix from $1,950 2026-06-23
Unclassified MEDIUM 5.3
CVE-2026-56311

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function that allows unauthenticated …

Mitigation only
Fix from $1,600 2026-06-22
Litellm MEDIUM 6.3
CVE-2026-12797

A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_h…

Fix: after 1.82.5
Fix from $1,600 2026-06-21
Litellm HIGH 7.5
CVE-2026-12771

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py …

Fix: 1.82.3+
Fix from $1,950 2026-06-21
Litellm HIGH 8.8
CVE-2026-12770

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endp…

Fix: 1.63.2+
Fix from $1,950 2026-06-21
Unclassified MEDIUM 6.3
CVE-2026-56295

Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-expiring API keys to bypass the …

Mitigation only
Fix from $1,600 2026-06-20
Unclassified MEDIUM 5.9
CVE-2026-12673

Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a seconda…

Mitigation only
Fix from $1,600 2026-06-20
Unclassified HIGH 7.1
CVE-2026-48089

DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instance with one or more public ass…

Patch available
Fix from $1,950 2026-06-19
Unclassified HIGH 7.1
CVE-2026-49338

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/dele…

Patch available
Fix from $1,950 2026-06-19
Unclassified MEDIUM 6.5
CVE-2026-50201

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.E…

Patch available
Fix from $1,600 2026-06-17
Identity Services Engine HIGH 7.5
CVE-2026-20190

A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This…

Mitigation only
Fix from $1,950 2026-06-17