Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.4 CVE-2026-70481 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update an… No fix yet Fix from $1,6002026-08-04 HIGH 7.1 CVE-2026-70475 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in p… No fix yet Fix from $1,9502026-08-04 HIGH 8.3 CVE-2026-70473 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-histor… No fix yet Fix from $1,9502026-08-04 HIGH 7.1 CVE-2026-13229 Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint. No fix yet Fix from $1,9502026-08-04 HIGH 7.2 CVE-2026-69252 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only b… No fix yet Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-18650 Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1. No fix yet Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-17070 Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects L… No fix yet Fix from $1,9502026-08-04 HIGH 8.2 CVE-2026-58080 In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role pe… Milo 1.1.5+ Fix from $1,9502026-08-04 MEDIUM 6.5 CVE-2026-63248 In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable dia… Milo 1.1.5+ Fix from $1,6002026-08-04 CRITICAL 9.3 CVE-2026-15958 The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions … No fix yet Fix from $2,3002026-08-04 HIGH 8.8 CVE-2026-66326 Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 151.0.4129.59+ Fix from $1,9502026-08-04 MEDIUM 6.2 CVE-2026-66311 Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 CRITICAL 9.8 CVE-2026-68979 Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer… Nifi 2.11.0+ Fix from $2,3002026-08-03 MEDIUM 5.8 CVE-2026-68585 SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata… No fix yet Fix from $1,6002026-08-03 HIGH 8.6 CVE-2026-68586 SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and… No fix yet Fix from $1,9502026-08-03 HIGH 8.6 CVE-2026-68587 SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and get… No fix yet Fix from $1,9502026-08-03 MEDIUM 5.4 CVE-2026-28147 Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorr… No fix yet Fix from $1,6002026-08-03 CRITICAL 9.8 CVE-2026-16300 The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the pass… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.4 CVE-2026-15930 The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value … No fix yet Fix from $2,3002026-08-03 MEDIUM 6.5 CVE-2026-16057 The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gati… No fix yet Fix from $1,6002026-08-03 HIGH 7.8 CVE-2026-20495 In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with U… No fix yet Fix from $1,9502026-08-03 HIGH 7.7 CVE-2026-20483 In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no… No fix yet Fix from $1,9502026-08-03 HIGH 7.2 CVE-2026-18571 A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi… Build Of Keycloak No fix yet Fix from $1,9502026-08-02 MEDIUM 6.5 CVE-2026-18573 A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs … Build Of Keycloak No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-18570 A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin… Build Of Keycloak No fix yet Fix from $1,6002026-08-02 HIGH 7.5 CVE-2026-16285 The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, a… No fix yet Fix from $1,9502026-08-02 MEDIUM 5.5 CVE-2026-15248 The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing … No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-13389 The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthen… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-17580 The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin f… No fix yet Fix from $1,6002026-08-01 MEDIUM 5.3 CVE-2026-11995 The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorizatio… No fix yet Fix from $1,6002026-08-01