Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Openclaw HIGH 8.3
CVE-2026-62195

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers…

Fix: 2026.6.6+
Fix from $1,950 2026-07-13
Openclaw HIGH 8.8
CVE-2026-62194

OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers t…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Unclassified HIGH 8.8
CVE-2026-59148

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on th…

Patch available
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.1
CVE-2026-59946

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resol…

Patch available
Fix from $1,600 2026-07-08
Unclassified HIGH 8.8
CVE-2026-9085

Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institu…

Mitigation only
Fix from $1,950 2026-07-05
Unclassified HIGH 8.9
CVE-2026-58424

Permanent Fork PR Workflow Approval Gate Bypass

Patch available
Fix from $1,950 2026-07-03
Mobile Vpn With Ssl HIGH 7.8
CVE-2026-13079

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privile…

Fix: 12.12.1 / 2026.2.1+
Fix from $1,950 2026-07-03
Unclassified MEDIUM 5.5
CVE-2026-13769

Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to re…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-58174

Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but constructs the Session object without …

Patch available
Fix from $1,600 2026-06-30
Safari MEDIUM 6.5
CVE-2026-43721

This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Unclassified HIGH 8.6
CVE-2026-55441

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 6.7
CVE-2026-9651

CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential…

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.5
CVE-2026-32315

motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the …

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.8
CVE-2026-12957

Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execu…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified HIGH 8.1
CVE-2026-49340

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdateP…

Mitigation only
Fix from $1,950 2026-06-19
Openclaw MEDIUM 5.5
CVE-2026-53856

OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly br…

Mitigation only
Fix from $1,600 2026-06-16
Prisma Access Agent HIGH 7.8
CVE-2026-0271

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code wit…

Fix: 26.2.1+
Fix from $1,950 2026-06-10
Unclassified HIGH 8.5
CVE-2026-50570

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…

Patch available
Fix from $1,950 2026-06-10
Unclassified HIGH 8.4
CVE-2026-26422

clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.

Patch available
Fix from $1,950 2026-06-06
Chrome MEDIUM 6.5
CVE-2026-10997

Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Unclassified HIGH 7.1
CVE-2026-10840

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 7.8
CVE-2026-50209

Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ow…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 8.2
CVE-2021-4481

Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that all…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.2
CVE-2021-4480

Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that all…

Mitigation only
Fix from $1,950 2026-06-02
Kiro Ide HIGH 8.8
CVE-2026-10591

Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to e…

Fix: 0.11+
Fix from $1,950 2026-06-02
Unclassified HIGH 7.8
CVE-2026-27788

Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is e…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified CRITICAL 10.0
CVE-2026-9508

Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly expo…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified HIGH 7.3
CVE-2026-7480

An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to …

Mitigation only
Fix from $1,950 2026-05-29
Unclassified HIGH 7.3
CVE-2026-8070

Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting i…

Mitigation only
Fix from $1,950 2026-05-29
Electerm HIGH 7.8
CVE-2026-45353

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.

Fix: 3.9.0+
Fix from $1,950 2026-05-28