Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.4
CVE-2026-70481

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update an…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.1
CVE-2026-70475

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in p…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.3
CVE-2026-70473

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-histor…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.1
CVE-2026-13229

Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.2
CVE-2026-69252

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only b…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-18650

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-17070

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects L…

No fix yet
Fix from $1,950 2026-08-04
Milo HIGH 8.2
CVE-2026-58080

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role pe…

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Milo MEDIUM 6.5
CVE-2026-63248

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable dia…

Fix: 1.1.5+
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.3
CVE-2026-15958

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions …

No fix yet
Fix from $2,300 2026-08-04
Edge Chromium HIGH 8.8
CVE-2026-66326

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 151.0.4129.59+
Fix from $1,950 2026-08-04
Edge Chromium MEDIUM 6.2
CVE-2026-66311

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Fix: 151.0.4129.59+
Fix from $1,600 2026-08-04
Nifi CRITICAL 9.8
CVE-2026-68979

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Unclassified MEDIUM 5.8
CVE-2026-68585

SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 8.6
CVE-2026-68586

SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.6
CVE-2026-68587

SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and get…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-28147

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorr…

No fix yet
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-16300

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the pass…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.4
CVE-2026-15930

The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value …

No fix yet
Fix from $2,300 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-16057

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gati…

No fix yet
Fix from $1,600 2026-08-03
Mt7925 Firmware HIGH 7.8
CVE-2026-20495

In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with U…

No fix yet
Fix from $1,950 2026-08-03
Mt8893 Firmware HIGH 7.7
CVE-2026-20483

In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no…

No fix yet
Fix from $1,950 2026-08-03
Build Of Keycloak HIGH 7.2
CVE-2026-18571

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi…

No fix yet
Fix from $1,950 2026-08-02
Build Of Keycloak MEDIUM 6.5
CVE-2026-18573

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs …

No fix yet
Fix from $1,600 2026-08-02
Build Of Keycloak MEDIUM 5.4
CVE-2026-18570

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin…

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 7.5
CVE-2026-16285

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, a…

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 5.5
CVE-2026-15248

The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing …

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 6.5
CVE-2026-13389

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthen…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 6.5
CVE-2026-17580

The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin f…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-11995

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorizatio…

No fix yet
Fix from $1,600 2026-08-01