Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.8
CVE-2026-72799

SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPa…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72800

SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retr…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72789

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous re…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72790

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata wi…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72791

SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in th…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63300

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_c…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-19656

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privil…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 7.1
CVE-2026-16494

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could…

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.4
CVE-2026-73296

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and…

No fix yet
Fix from $5,750 2026-08-12
Unclassified MEDIUM 5.9
CVE-2026-69107

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

No fix yet
Fix from $4,000 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-68971

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finis…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-68758

A low-privileged authenticated user may access restricted support information under specific conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-73405

An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) strea…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-73287

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/s…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-73265

RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadP…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-68754

A repository publisher without delete permission may modify protected package content under specific conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-68753

An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.1
CVE-2026-66375

A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-66377

An unauthenticated user may access restricted repository information under specific conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-47233

Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modu…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-47226

Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.0
CVE-2026-53996

NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to i…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-18789

The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated atta…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-18035

The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attacker…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.2
CVE-2026-64954

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-73249

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.2
CVE-2026-48763

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{b…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-15606

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-69115

OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-only management API endpoints …

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-18704

An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against co…

No fix yet
Fix from $4,000 2026-08-11