Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.2 CVE-2026-54097 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Patch available Fix from $1,9502026-06-25 HIGH 7.7 CVE-2026-9099 A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticate… Build Of Keycloak 26.4.13 / 26.6.4+ Fix from $1,9502026-06-25 MEDIUM 6.8 CVE-2026-55411 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lt… Mitigation only Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-56013 Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions. Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.4 CVE-2026-5309 GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under ce… GitLab 18.11.6 / 19.0.3+ Fix from $1,6002026-06-25 HIGH 7.1 CVE-2026-52812 Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS-root>/<oid[0]>/<oid[1]>/<oid… Patch available Fix from $1,9502026-06-24 HIGH 7.5 CVE-2026-52799 Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the… Mitigation only Fix from $1,9502026-06-24 HIGH 7.6 CVE-2026-55583 Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct … Mitigation only Fix from $1,9502026-06-24 HIGH 7.1 CVE-2026-27708 FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method ac… Mitigation only Fix from $1,9502026-06-24 MEDIUM 6.9 CVE-2026-47378 NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, Public shared-view endpoints exposed values from columns that the view… Mitigation only Fix from $1,6002026-06-23 MEDIUM 5.1 CVE-2025-64105 FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online service businesses. Versions 0… Mitigation only Fix from $1,6002026-06-23 HIGH 7.7 CVE-2026-54322 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organization … Mitigation only Fix from $1,9502026-06-23 MEDIUM 6.5 CVE-2026-54324 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, a cross-tenant authoriz… Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.5 CVE-2026-54009 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/chat/completions accepts… Open Webui 0.9.6+ Fix from $1,6002026-06-23 HIGH 8.3 CVE-2026-54010 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated u… Open Webui 0.9.6+ Fix from $1,9502026-06-23 MEDIUM 6.4 CVE-2026-54015 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI's prompt version-histor… Open Webui 0.9.6+ Fix from $1,6002026-06-23 HIGH 8.4 CVE-2026-55255 KEVEPSS 29% Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabili… Langflow 1.9.1+ Fix from $1,9502026-06-23 HIGH 8.1 CVE-2026-45732 n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints autho… N8n 1.123.43 / 2.20.7+ Fix from $1,9502026-06-23 HIGH 8.8 CVE-2026-33760 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints … Langflow 1.9.0+ Fix from $1,9502026-06-23 HIGH 7.1 CVE-2025-62180 Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain a… Mitigation only Fix from $1,9502026-06-23 HIGH 8.1 CVE-2026-56784 OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authentica… Mitigation only Fix from $1,9502026-06-23 HIGH 7.2 CVE-2026-56222 Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify app_id ownership during app-… Mitigation only Fix from $1,9502026-06-23 MEDIUM 6.5 CVE-2026-48067 Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from fi… Mitigation only Fix from $1,6002026-06-22 MEDIUM 6.4 CVE-2026-6062 Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subsc… Mattermost Server 10.11.18 / 11.5.6+ Fix from $1,6002026-06-22 HIGH 8.8 CVE-2026-56424 MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/edita… Misp 2.5.42+ Fix from $1,9502026-06-22 CRITICAL 9.4 CVE-2026-56422 Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreig… Patch available Fix from $2,3002026-06-22 MEDIUM 6.5 CVE-2026-56229 Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that allows attackers to access b… Mitigation only Fix from $1,6002026-06-21 HIGH 8.3 CVE-2026-56215 Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpo… Mitigation only Fix from $1,9502026-06-20 HIGH 7.1 CVE-2026-49338 gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/dele… Patch available Fix from $1,9502026-06-19 HIGH 7.1 CVE-2026-49339 gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6dd71e6a3c966867ef8c900d359a7d… Patch available Fix from $1,9502026-06-19