Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 7.7
CVE-2026-54322

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organization …

Mitigation only
Fix from $1,950 2026-06-23
Open Webui MEDIUM 6.5
CVE-2026-54019

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI added collection-level …

Fix: 0.9.6+
Fix from $1,600 2026-06-23
Open Webui HIGH 8.3
CVE-2026-54010

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated u…

Fix: 0.9.6+
Fix from $1,950 2026-06-23
Open Webui HIGH 7.1
CVE-2026-54012

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can cre…

Fix: 0.9.6+
Fix from $1,950 2026-06-23
Bootimus HIGH 8.8
CVE-2026-56115

Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actio…

Fix: after 0.1.70
Fix from $1,950 2026-06-23
Unclassified MEDIUM 6.5
CVE-2026-56695

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load…

Patch available
Fix from $1,600 2026-06-23
Unclassified MEDIUM 5.4
CVE-2026-56696

OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controll…

Patch available
Fix from $1,600 2026-06-23
Unclassified MEDIUM 6.5
CVE-2026-56402

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role auth…

Patch available
Fix from $1,600 2026-06-23
Unclassified CRITICAL 10.0
CVE-2026-27604

FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas…

Mitigation only
Fix from $2,300 2026-06-23
Cluster Logging Operator MEDIUM 6.8
CVE-2026-10609

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output d…

Mitigation only
Fix from $1,600 2026-06-23
Unclassified HIGH 7.1
CVE-2026-56280

Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel running…

Mitigation only
Fix from $1,950 2026-06-22
Unclassified MEDIUM 6.5
CVE-2026-48500

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can con…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified MEDIUM 6.9
CVE-2026-8934

A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthentica…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified HIGH 8.2
CVE-2026-56104

Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user ses…

Patch available
Fix from $1,950 2026-06-22
Mattermost Server MEDIUM 5.4
CVE-2026-5139

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{se…

Fix: 10.11.18 / 11.5.6+
Fix from $1,600 2026-06-22
Misp HIGH 8.8
CVE-2026-56424

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/edita…

Fix: 2.5.42+
Fix from $1,950 2026-06-22
Misp HIGH 8.8
CVE-2026-56423

MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handle…

Fix: 2.5.42+
Fix from $1,950 2026-06-22
Nifi HIGH 7.2
CVE-2026-44914

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Per…

Fix: 2.10.0+
Fix from $1,950 2026-06-22
Unclassified MEDIUM 5.3
CVE-2026-7859

The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated a…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified HIGH 8.8
CVE-2026-56396

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administ…

Mitigation only
Fix from $1,950 2026-06-21
Unclassified HIGH 7.5
CVE-2026-56341

AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPa…

Mitigation only
Fix from $1,950 2026-06-20
Unclassified HIGH 7.5
CVE-2026-11912

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to…

Mitigation only
Fix from $1,950 2026-06-20
Unclassified MEDIUM 6.5
CVE-2026-12119

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' sho…

Mitigation only
Fix from $1,600 2026-06-20
Unclassified MEDIUM 5.3
CVE-2026-56213

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgRES…

Mitigation only
Fix from $1,600 2026-06-20
Exchange Online CRITICAL 9.6
CVE-2026-48582

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-06-19
Unclassified HIGH 8.1
CVE-2026-49291

mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only O…

Mitigation only
Fix from $1,950 2026-06-19
Unclassified MEDIUM 5.3
CVE-2026-12238

The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. Th…

No fix yet
Fix from $1,600 2026-06-19
Unclassified HIGH 8.8
CVE-2026-49357

Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop appli…

Patch available
Fix from $1,950 2026-06-19
Unclassified MEDIUM 5.3
CVE-2026-3640

The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin reg…

Mitigation only
Fix from $1,600 2026-06-19
Unclassified MEDIUM 5.3
CVE-2026-6798

The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5…

No fix yet
Fix from $1,600 2026-06-19