Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.4
CVE-2026-18709

An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepa…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-69113

Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on…

No fix yet
Fix from $4,000 2026-08-11
Azure Cyclecloud HIGH 8.8
CVE-2026-70340

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $4,900 2026-08-11
Azure Cyclecloud MEDIUM 6.5
CVE-2026-65806

Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $4,000 2026-08-11
Exchange Server MEDIUM 6.5
CVE-2026-62915

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

Fix: 15.02.2562.046+
Fix from $4,000 2026-08-11
Windows 10 1809 MEDIUM 5.5
CVE-2026-61936

Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,000 2026-08-11
Visual Studio Code HIGH 8.8
CVE-2026-59113

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $4,900 2026-08-11
Dynamics 365 Business Central 2024 MEDIUM 6.5
CVE-2026-40375

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

Fix: 26.0.50788 / 27.0.50789+
Fix from $4,000 2026-08-11
Unclassified HIGH 7.1
CVE-2026-48495

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trus…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-42142

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate worksp…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.6
CVE-2026-19539

Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated use…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73140

Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal commen…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73155

Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users …

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-14548

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing an…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.8
CVE-2026-58243

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to exe…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.3
CVE-2026-44764

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted …

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.3
CVE-2026-44765

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-58237

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit t…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.7
CVE-2025-30237

The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certa…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-72918

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 7.1
CVE-2026-72910

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 8.5
CVE-2026-18947

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a spec…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 8.8
CVE-2026-72883

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72876

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getA…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 8.2
CVE-2026-14886

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated call…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72864

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/serve…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 8.8
CVE-2026-72866

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validat…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72868

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the acce…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72863

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 7.5
CVE-2026-71962

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that …

No fix yet
Fix from $4,900 2026-08-10