Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.4
CVE-2026-63082

Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.6
CVE-2026-57206

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-55440

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/serve…

Patch available
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.3
CVE-2026-15106

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up t…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-53447

Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoard…

Patch available
Fix from $1,600 2026-07-15
Unclassified MEDIUM 6.5
CVE-2026-52892

Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.chec…

Patch available
Fix from $1,600 2026-07-15
Unclassified HIGH 7.6
CVE-2026-53444

Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/…

Patch available
Fix from $1,950 2026-07-15
Unclassified HIGH 7.1
CVE-2026-53445

Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board b…

Patch available
Fix from $1,950 2026-07-15
N8n Mcp CRITICAL 9.9
CVE-2026-54052

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with…

Fix: 2.56.1+
Fix from $2,300 2026-07-15
Unclassified MEDIUM 5.3
CVE-2026-33684

WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in sign…

Mitigation only
Fix from $1,600 2026-07-15
Cilium HIGH 8.9
CVE-2026-56742

Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users wi…

Fix: 1.17.17 / 1.18.11+
Fix from $1,950 2026-07-15
Mcp Python Sdk HIGH 7.6
CVE-2026-52870

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers in…

Fix: 1.27.2+
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.4
CVE-2026-62348

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-priv…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 7.1
CVE-2026-59255

BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any a…

Patch available
Fix from $1,950 2026-07-15
Better Auth HIGH 7.7
CVE-2026-53514

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtain…

Fix: 1.6.11+
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.5
CVE-2025-32781

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does…

Patch available
Fix from $1,600 2026-07-15
Unclassified MEDIUM 5.3
CVE-2026-46459

ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote atta…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 6.5
CVE-2026-61440

PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared …

Patch available
Fix from $1,600 2026-07-15
Unclassified HIGH 7.7
CVE-2026-14251

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objec…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.3
CVE-2026-15752

A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the fil…

Patch available
Fix from $1,950 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-53633

Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarde…

Patch available
Fix from $2,300 2026-07-14
Sharepoint Server HIGH 8.8
CVE-2026-55052

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20434+
Fix from $1,950 2026-07-14
Azure Cyclecloud MEDIUM 6.5
CVE-2026-58279

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

Fix: 8.9.1+
Fix from $1,600 2026-07-14
Unclassified MEDIUM 5.3
CVE-2026-60118

Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden …

Patch available
Fix from $1,600 2026-07-14
Unclassified MEDIUM 5.4
CVE-2026-60119

Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to …

Patch available
Fix from $1,600 2026-07-14
Unclassified HIGH 8.2
CVE-2026-14504

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda …

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.4
CVE-2026-12988

The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the use…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 5.3
CVE-2026-11802

The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 7.5
CVE-2026-62328

9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user …

Mitigation only
Fix from $1,950 2026-07-13
Openclaw HIGH 7.1
CVE-2026-62191

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13