Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 8.3 CVE-2026-58284 Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 CRITICAL 10.0 CVE-2026-57983 Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. Edge Chromium 150.0.4078.48+ Fix from $2,3002026-07-03 HIGH 7.6 CVE-2026-50279 Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, theEntriesController::actionSaveEntry() performs ent… Patch available Fix from $1,9502026-07-02 HIGH 7.1 CVE-2026-56320 Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_id parameter without validatin… Mitigation only Fix from $1,9502026-06-30 HIGH 7.7 CVE-2026-56350 n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attacke… N8n 2.8.0+ Fix from $1,9502026-06-30 HIGH 7.6 CVE-2026-56249 Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authenticated users to overwrite ex… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.8 CVE-2026-7663 IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t… Langflow 1.10.0+ Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-6556 @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string … Fastify\/express 4.0.7+ Fix from $2,3002026-06-30 HIGH 8.1 CVE-2026-49877 Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the… Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-55956 Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method o… Tomcat 9.0.119 / 10.1.56+ Fix from $1,6002026-06-29 MEDIUM 5.0 CVE-2026-13591 A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/managers/ChannelBridge.ts of … Patch available Fix from $1,6002026-06-29 MEDIUM 5.4 CVE-2026-13549 A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file appli… Mitigation only Fix from $1,6002026-06-29 MEDIUM 5.0 CVE-2026-13534 A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryServi… Patch available Fix from $1,6002026-06-29 MEDIUM 5.6 CVE-2026-13524 A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/servic… Patch available Fix from $1,6002026-06-29 MEDIUM 6.3 CVE-2026-13512 A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/ser… Patch available Fix from $1,6002026-06-28 MEDIUM 5.5 CVE-2026-13508 A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component… Patch available Fix from $1,6002026-06-28 MEDIUM 6.7 CVE-2026-49278 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.1… Mitigation only Fix from $1,6002026-06-24 HIGH 7.6 CVE-2026-56231 Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.8 CVE-2026-46552 NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the same base-member capabilities as… Mitigation only Fix from $1,6002026-06-23 HIGH 7.1 CVE-2026-54012 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can cre… Open Webui 0.9.6+ Fix from $1,9502026-06-23 MEDIUM 5.3 CVE-2026-56311 Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function that allows unauthenticated … Mitigation only Fix from $1,6002026-06-22 MEDIUM 6.3 CVE-2026-12797 A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_h… Litellm after 1.82.5 Fix from $1,6002026-06-21 HIGH 7.5 CVE-2026-12771 A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py … Litellm 1.82.3+ Fix from $1,9502026-06-21 HIGH 8.8 CVE-2026-12770 A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endp… Litellm 1.63.2+ Fix from $1,9502026-06-21 MEDIUM 6.3 CVE-2026-56295 Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-expiring API keys to bypass the … Mitigation only Fix from $1,6002026-06-20 MEDIUM 5.9 CVE-2026-12673 Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a seconda… Mitigation only Fix from $1,6002026-06-20 HIGH 7.1 CVE-2026-48089 DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instance with one or more public ass… Patch available Fix from $1,9502026-06-19 HIGH 7.1 CVE-2026-49338 gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/dele… Patch available Fix from $1,9502026-06-19 MEDIUM 6.5 CVE-2026-50201 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.E… Patch available Fix from $1,6002026-06-17 HIGH 7.5 CVE-2026-20190 A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This… Identity Services Engine Mitigation only Fix from $1,9502026-06-17