Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 7.2
CVE-2026-54097

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Patch available
Fix from $1,950 2026-06-25
Build Of Keycloak HIGH 7.7
CVE-2026-9099

A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticate…

Fix: 26.4.13 / 26.6.4+
Fix from $1,950 2026-06-25
Unclassified MEDIUM 6.8
CVE-2026-55411

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lt…

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 6.5
CVE-2026-56013

Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.

Mitigation only
Fix from $1,600 2026-06-25
GitLab MEDIUM 5.4
CVE-2026-5309

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under ce…

Fix: 18.11.6 / 19.0.3+
Fix from $1,600 2026-06-25
Unclassified HIGH 7.1
CVE-2026-52812

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS-root>/<oid[0]>/<oid[1]>/<oid…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 7.5
CVE-2026-52799

Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.6
CVE-2026-55583

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct …

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.1
CVE-2026-27708

FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method ac…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 6.9
CVE-2026-47378

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, Public shared-view endpoints exposed values from columns that the view…

Mitigation only
Fix from $1,600 2026-06-23
Unclassified MEDIUM 5.1
CVE-2025-64105

FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online service businesses. Versions 0…

Mitigation only
Fix from $1,600 2026-06-23
Unclassified HIGH 7.7
CVE-2026-54322

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organization …

Mitigation only
Fix from $1,950 2026-06-23
Unclassified MEDIUM 6.5
CVE-2026-54324

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, a cross-tenant authoriz…

Mitigation only
Fix from $1,600 2026-06-23
Open Webui MEDIUM 6.5
CVE-2026-54009

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/chat/completions accepts…

Fix: 0.9.6+
Fix from $1,600 2026-06-23
Open Webui HIGH 8.3
CVE-2026-54010

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated u…

Fix: 0.9.6+
Fix from $1,950 2026-06-23
Open Webui MEDIUM 6.4
CVE-2026-54015

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI's prompt version-histor…

Fix: 0.9.6+
Fix from $1,600 2026-06-23
Langflow HIGH 8.4
CVE-2026-55255 KEVEPSS 29%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabili…

Fix: 1.9.1+
Fix from $1,950 2026-06-23
N8n HIGH 8.1
CVE-2026-45732

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints autho…

Fix: 1.123.43 / 2.20.7+
Fix from $1,950 2026-06-23
Langflow HIGH 8.8
CVE-2026-33760

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints …

Fix: 1.9.0+
Fix from $1,950 2026-06-23
Unclassified HIGH 7.1
CVE-2025-62180

Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain a…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified HIGH 8.1
CVE-2026-56784

OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authentica…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified HIGH 7.2
CVE-2026-56222

Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify app_id ownership during app-…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified MEDIUM 6.5
CVE-2026-48067

Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from fi…

Mitigation only
Fix from $1,600 2026-06-22
Mattermost Server MEDIUM 6.4
CVE-2026-6062

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subsc…

Fix: 10.11.18 / 11.5.6+
Fix from $1,600 2026-06-22
Misp HIGH 8.8
CVE-2026-56424

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/edita…

Fix: 2.5.42+
Fix from $1,950 2026-06-22
Unclassified CRITICAL 9.4
CVE-2026-56422

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreig…

Patch available
Fix from $2,300 2026-06-22
Unclassified MEDIUM 6.5
CVE-2026-56229

Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that allows attackers to access b…

Mitigation only
Fix from $1,600 2026-06-21
Unclassified HIGH 8.3
CVE-2026-56215

Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpo…

Mitigation only
Fix from $1,950 2026-06-20
Unclassified HIGH 7.1
CVE-2026-49338

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/dele…

Patch available
Fix from $1,950 2026-06-19
Unclassified HIGH 7.1
CVE-2026-49339

gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6dd71e6a3c966867ef8c900d359a7d…

Patch available
Fix from $1,950 2026-06-19