Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 6.3 CVE-2026-48115 Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.3 CVE-2026-18631 A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/sr… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.4 CVE-2026-18584 A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of … No fix yet Fix from $1,6002026-08-03 MEDIUM 6.4 CVE-2026-67332 @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens fo… No fix yet Fix from $1,6002026-08-01 HIGH 7.7 CVE-2026-14538 An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1… Mcp Toolbox For Databases after 1.4.0 Fix from $1,9502026-07-31 CRITICAL 9.3 CVE-2026-48499 Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut… No fix yet Fix from $2,3002026-07-30 MEDIUM 5.3 CVE-2026-23981 An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboar… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-41187 Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy,… Calico 3.21.7 / 3.22.4+ Fix from $1,6002026-07-30 MEDIUM 5.3 CVE-2026-66488 Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 Gridbox 2.20.2+ Fix from $1,6002026-07-29 MEDIUM 6.5 CVE-2026-18207 A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of … Build Of Keycloak No fix yet Fix from $1,6002026-07-29 HIGH 7.1 CVE-2026-47726 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGe… No fix yet Fix from $1,9502026-07-28 MEDIUM 6.5 CVE-2026-61487 Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypas… Activemq 5.19.9 / 6.2.8+ Fix from $1,6002026-07-28 MEDIUM 6.5 CVE-2026-64743 An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6,… Ipados 26.6+ Fix from $1,6002026-07-27 MEDIUM 5.5 CVE-2026-64711 This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8… Ipados 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-43792 An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to acce… Safari 26.6+ Fix from $1,6002026-07-27 MEDIUM 5.5 CVE-2026-43775 An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be abl… macOS 15.7.8 / 26.6+ Fix from $1,6002026-07-27 MEDIUM 5.5 CVE-2026-43756 A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may … macOS 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 HIGH 8.2 CVE-2026-64642 Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applica… Next.js 16.2.11+ Fix from $1,9502026-07-27 MEDIUM 5.0 CVE-2026-17531 A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/route… No fix yet Fix from $1,6002026-07-27 MEDIUM 6.3 CVE-2026-17529 A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The … No fix yet Fix from $1,6002026-07-27 MEDIUM 6.3 CVE-2026-17530 A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the… No fix yet Fix from $1,6002026-07-27 MEDIUM 6.3 CVE-2026-17434 A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of t… No fix yet Fix from $1,6002026-07-26 MEDIUM 5.3 CVE-2026-17433 A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk… No fix yet Fix from $1,6002026-07-26 HIGH 7.5 CVE-2026-62835 Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. Azure Portal No fix yet Fix from $1,9502026-07-24 CRITICAL 9.9 CVE-2026-56160 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. Azure Red Hat Openshift No fix yet Fix from $2,3002026-07-24 MEDIUM 5.4 CVE-2026-62563 Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecte… Work In Process after 12.2.15 Fix from $1,6002026-07-21 MEDIUM 6.1 CVE-2026-62444 Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a… E Business Suite after 12.2.15 Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-61082 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily… Mysql Connectors No fix yet Fix from $1,6002026-07-21 MEDIUM 5.4 CVE-2026-60957 Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that ar… E Business Suite after 12.2.15 Fix from $1,6002026-07-21 MEDIUM 5.4 CVE-2026-60911 Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affect… Property Manager after 12.2.15 Fix from $1,6002026-07-21