Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.3 CVE-2026-62195 OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers… Openclaw 2026.6.6+ Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-62194 OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers t… Openclaw 2026.6.9+ Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-59148 Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on th… Patch available Fix from $1,9502026-07-09 MEDIUM 6.1 CVE-2026-59946 Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resol… Patch available Fix from $1,6002026-07-08 HIGH 8.8 CVE-2026-9085 Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institu… Mitigation only Fix from $1,9502026-07-05 HIGH 8.9 CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass Patch available Fix from $1,9502026-07-03 HIGH 7.8 CVE-2026-13079 A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privile… Mobile Vpn With Ssl 12.12.1 / 2026.2.1+ Fix from $1,9502026-07-03 MEDIUM 5.5 CVE-2026-13769 Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to re… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-58174 Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but constructs the Session object without … Patch available Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-43721 This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t… Safari 26.5.2+ Fix from $1,6002026-06-29 HIGH 8.6 CVE-2026-55441 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions… Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.7 CVE-2026-9651 CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential… Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.5 CVE-2026-32315 motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the … Mitigation only Fix from $1,6002026-06-24 HIGH 7.8 CVE-2026-12957 Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execu… Mitigation only Fix from $1,9502026-06-23 HIGH 8.1 CVE-2026-49340 gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdateP… Mitigation only Fix from $1,9502026-06-19 MEDIUM 5.5 CVE-2026-53856 OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly br… Openclaw Mitigation only Fix from $1,6002026-06-16 HIGH 7.8 CVE-2026-0271 A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code wit… Prisma Access Agent 26.2.1+ Fix from $1,9502026-06-10 HIGH 8.5 CVE-2026-50570 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 HIGH 8.4 CVE-2026-26422 clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation. Patch available Fix from $1,9502026-06-06 MEDIUM 6.5 CVE-2026-10997 Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 7.1 CVE-2026-10840 A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write… Mitigation only Fix from $1,9502026-06-04 HIGH 7.8 CVE-2026-50209 Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ow… Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 HIGH 8.2 CVE-2021-4481 Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that all… Mitigation only Fix from $1,9502026-06-02 HIGH 8.2 CVE-2021-4480 Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that all… Mitigation only Fix from $1,9502026-06-02 HIGH 8.8 CVE-2026-10591 Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to e… Kiro Ide 0.11+ Fix from $1,9502026-06-02 HIGH 7.8 CVE-2026-27788 Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is e… Mitigation only Fix from $1,9502026-06-01 CRITICAL 10.0 CVE-2026-9508 Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly expo… Mitigation only Fix from $2,3002026-05-29 HIGH 7.3 CVE-2026-7480 An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to … Mitigation only Fix from $1,9502026-05-29 HIGH 7.3 CVE-2026-8070 Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting i… Mitigation only Fix from $1,9502026-05-29 HIGH 7.8 CVE-2026-45353 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0. Electerm 3.9.0+ Fix from $1,9502026-05-28