Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.4
CVE-2022-42479

Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sol…

Mitigation only
Fix from $1,600 2026-06-11
Pan Os HIGH 7.2
CVE-2026-0272

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Int…

Fix: 10.2.7 / 10.2.10+
Fix from $1,950 2026-06-10
Unclassified HIGH 7.7
CVE-2026-49821

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…

Patch available
Fix from $1,950 2026-06-10
Unclassified HIGH 7.7
CVE-2026-49822

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…

Patch available
Fix from $1,950 2026-06-10
Unclassified CRITICAL 9.8
CVE-2026-46614

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…

Patch available
Fix from $2,300 2026-06-10
Plane HIGH 8.3
CVE-2026-46558

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated…

Fix: 1.3.1+
Fix from $1,950 2026-06-10
Unclassified CRITICAL 9.1
CVE-2026-45550

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smo…

Mitigation only
Fix from $2,300 2026-06-10
Unclassified CRITICAL 9.9
CVE-2026-45552

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares …

Mitigation only
Fix from $2,300 2026-06-10
Unclassified HIGH 8.5
CVE-2026-45549

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/a…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified MEDIUM 6.5
CVE-2026-11852

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifa…

Mitigation only
Fix from $1,600 2026-06-10
Qumagie HIGH 7.5
CVE-2026-26237

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthor…

Fix: 2.9.0+
Fix from $1,950 2026-06-10
Openemr HIGH 8.7
CVE-2026-46518

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-sit…

Fix: 8.0.0.1+
Fix from $1,950 2026-06-10
Unclassified MEDIUM 6.5
CVE-2026-49956

Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to ot…

Patch available
Fix from $1,600 2026-06-09
Visual Studio Code CRITICAL 9.6
CVE-2026-47281

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Fix: 1.123.1+
Fix from $2,300 2026-06-09
Unclassified HIGH 8.1
CVE-2026-49948

Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POS…

Patch available
Fix from $1,950 2026-06-09
Unclassified MEDIUM 5.3
CVE-2026-47352

Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to f…

Patch available
Fix from $1,600 2026-06-09
Unclassified HIGH 8.7
CVE-2026-49741

Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via Dat…

Patch available
Fix from $1,950 2026-06-09
Unclassified HIGH 7.2
CVE-2026-47343

Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of …

Patch available
Fix from $1,950 2026-06-09
Unclassified HIGH 7.6
CVE-2026-47346

Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form …

Patch available
Fix from $1,950 2026-06-09
Unclassified MEDIUM 5.3
CVE-2026-47349

Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify.…

Patch available
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.3
CVE-2026-47350

Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions…

Patch available
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.3
CVE-2026-47351

Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to …

Patch available
Fix from $1,600 2026-06-09
Unclassified HIGH 7.6
CVE-2026-11607

Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without den…

Patch available
Fix from $1,950 2026-06-09
Unclassified MEDIUM 5.3
CVE-2026-4986

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing una…

Mitigation only
Fix from $1,600 2026-06-09
Qumagie HIGH 7.5
CVE-2026-26236

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthor…

Fix: 2.9.0+
Fix from $1,950 2026-06-09
Unclassified MEDIUM 6.6
CVE-2026-44754

The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permi…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified HIGH 7.1
CVE-2026-44751

Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker to execute a report generation…

Mitigation only
Fix from $1,950 2026-06-09
Unclassified CRITICAL 9.8
CVE-2026-39910

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to f…

Mitigation only
Fix from $2,300 2026-06-08
Flowise HIGH 8.8
CVE-2026-46444

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assist…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Unclassified MEDIUM 5.3
CVE-2026-8502

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all …

Mitigation only
Fix from $1,600 2026-06-06