Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Mem0 MEDIUM 6.5
CVE-2026-31244

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoi…

Mitigation only
Fix from $1,600 2026-05-12
Fortisandbox CRITICAL 9.8
CVE-2026-26083

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 throug…

Fix: 4.4.9 / 5.0.2+
Fix from $2,300 2026-05-12
Unclassified MEDIUM 5.3
CVE-2026-25431

Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects H…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 5.4
CVE-2026-45210

Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured Access Control Security Level…

No fix yet
Fix from $1,600 2026-05-12
Unclassified MEDIUM 5.3
CVE-2026-45212

Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting Incorrectly Configured Access…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 5.3
CVE-2026-6708

The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and includi…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 5.3
CVE-2026-5693

The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 8.2
CVE-2026-39432

Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affect…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified MEDIUM 5.4
CVE-2026-40132

Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker coul…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.3
CVE-2026-40133

Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify …

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 7.7
CVE-2026-43885

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.j…

Patch available
Fix from $1,950 2026-05-11
macOS MEDIUM 5.5
CVE-2026-20696

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive …

Fix: 26.4+
Fix from $1,600 2026-05-11
Openclaw HIGH 7.1
CVE-2026-45001

OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to pro…

Fix: 2026.4.20+
Fix from $1,950 2026-05-11
Openclaw MEDIUM 5.3
CVE-2026-44994

OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that allows unauthenticated att…

Fix: 2026.4.22+
Fix from $1,600 2026-05-11
Server MEDIUM 5.4
CVE-2026-43638

Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitr…

Fix: 2026.4.1+
Fix from $1,600 2026-05-11
Server CRITICAL 9.1
CVE-2026-43639

Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organizati…

Fix: 2026.4.0+
Fix from $2,300 2026-05-11
Unclassified HIGH 7.5
CVE-2026-33357

In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 7.5
CVE-2026-33359

In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable with…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified CRITICAL 9.4
CVE-2026-42613

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and acc…

Patch available
Fix from $2,300 2026-05-11
Automation Platform HIGH 8.8
CVE-2026-32658

Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access coul…

Fix: 2.0.0.0+
Fix from $1,950 2026-05-11
Unclassified CRITICAL 9.8
CVE-2021-47932

WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts …

Mitigation only
Fix from $2,300 2026-05-10
Unclassified CRITICAL 9.4
CVE-2026-42569

phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access…

Patch available
Fix from $2,300 2026-05-09
Arcane HIGH 7.5
CVE-2026-42461

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/template…

Fix: 1.18.0+
Fix from $1,950 2026-05-09
Argo Workflows HIGH 8.3
CVE-2026-42297

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version…

Fix: 4.0.5+
Fix from $1,950 2026-05-09
Kirby MEDIUM 6.5
CVE-2026-42069

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by …

Fix: 4.9.0 / 5.4.0+
Fix from $1,600 2026-05-09
Kirby MEDIUM 6.5
CVE-2026-42137

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not…

Fix: 4.9.0 / 5.4.0+
Fix from $1,600 2026-05-09
Unclassified CRITICAL 9.3
CVE-2026-44125

SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthe…

Mitigation only
Fix from $2,300 2026-05-08
Nifi HIGH 8.8
CVE-2026-39816

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi…

Fix: 2.9.0+
Fix from $1,950 2026-05-08
Unclassified HIGH 8.6
CVE-2026-8077

Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend lacks authorization controls,…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified MEDIUM 5.3
CVE-2026-27416

Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affec…

Mitigation only
Fix from $1,600 2026-05-07