Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
CRITICAL 9.9 CVE-2026-55166 Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-si… Fix unknown Fix from $5,7502026-08-18 MEDIUM 6.5 CVE-2026-48744 Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can in… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-19608 A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. T… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2024-14045 A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-19994 A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-… Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.4 CVE-2026-19986 A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the… Fix unknown Fix from $4,0002026-08-17 HIGH 8.3 CVE-2026-19979 A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, M… Fix unknown Fix from $4,9002026-08-17 MEDIUM 5.4 CVE-2026-19966 A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/… Fix unknown Fix from $4,0002026-08-17 HIGH 8.8 CVE-2026-16879 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization usin… No fix yet Fix from $4,9002026-08-14 CRITICAL 9.1 CVE-2026-73421 NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for … No fix yet Fix from $5,7502026-08-13 HIGH 7.1 CVE-2026-18509 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could all… I No fix yet Fix from $4,9002026-08-13 CRITICAL 9.6 CVE-2026-73644 OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org… No fix yet Fix from $5,7502026-08-13 MEDIUM 5.3 CVE-2026-3835 The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient … No fix yet Fix from $4,0002026-08-13 CRITICAL 9.8 CVE-2026-10543 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query. Db2 No fix yet Fix from $5,7502026-08-12 MEDIUM 6.5 CVE-2026-72786 Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change… No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-18499 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. Websphere Application Server No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-72907 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py … No fix yet Fix from $4,0002026-08-10 HIGH 8.7 CVE-2026-47663 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 CRITICAL 9.3 CVE-2026-59118 Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. Power Apps No fix yet Fix from $2,3002026-08-07 CRITICAL 9.3 CVE-2026-18367 A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 a… No fix yet Fix from $2,3002026-08-06 MEDIUM 6.3 CVE-2026-19006 A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Gg… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18997 A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18998 A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.t… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18992 A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/exec… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18818 A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views… No fix yet Fix from $1,6002026-08-04 HIGH 7.1 CVE-2026-70472 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpo… No fix yet Fix from $1,9502026-08-04 MEDIUM 6.3 CVE-2026-18773 A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gate… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.3 CVE-2026-18722 A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.3 CVE-2026-18723 A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-… No fix yet Fix from $1,6002026-08-04 MEDIUM 5.3 CVE-2026-18720 A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of t… No fix yet Fix from $1,6002026-08-04