Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.6 CVE-2026-57206 SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.5 CVE-2026-55440 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/serve… Patch available Fix from $1,6002026-07-16 MEDIUM 5.3 CVE-2026-15106 The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up t… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.5 CVE-2026-53447 Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoard… Patch available Fix from $1,6002026-07-15 MEDIUM 6.5 CVE-2026-52892 Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.chec… Patch available Fix from $1,6002026-07-15 HIGH 7.6 CVE-2026-53444 Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/… Patch available Fix from $1,9502026-07-15 HIGH 7.1 CVE-2026-53445 Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board b… Patch available Fix from $1,9502026-07-15 CRITICAL 9.9 CVE-2026-54052 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with… N8n Mcp 2.56.1+ Fix from $2,3002026-07-15 MEDIUM 5.3 CVE-2026-33684 WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in sign… Mitigation only Fix from $1,6002026-07-15 HIGH 8.9 CVE-2026-56742 Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users wi… Cilium 1.17.17 / 1.18.11+ Fix from $1,9502026-07-15 HIGH 7.6 CVE-2026-52870 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers in… Mcp Python Sdk 1.27.2+ Fix from $1,9502026-07-15 MEDIUM 5.4 CVE-2026-62348 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-priv… Mitigation only Fix from $1,6002026-07-15 HIGH 7.1 CVE-2026-59255 BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any a… Patch available Fix from $1,9502026-07-15 HIGH 7.7 CVE-2026-53514 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtain… Better Auth 1.6.11+ Fix from $1,9502026-07-15 MEDIUM 6.5 CVE-2025-32781 Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does… Patch available Fix from $1,6002026-07-15 MEDIUM 5.3 CVE-2026-46459 ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote atta… Mitigation only Fix from $1,6002026-07-15 MEDIUM 6.5 CVE-2026-61440 PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared … Patch available Fix from $1,6002026-07-15 HIGH 7.7 CVE-2026-14251 A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objec… Mitigation only Fix from $1,9502026-07-15 HIGH 7.3 CVE-2026-15752 A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the fil… Patch available Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-53633 Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarde… Patch available Fix from $2,3002026-07-14 HIGH 8.8 CVE-2026-55052 Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20434+ Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-58279 Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. Azure Cyclecloud 8.9.1+ Fix from $1,6002026-07-14 MEDIUM 5.3 CVE-2026-60118 Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden … Patch available Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-60119 Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to … Patch available Fix from $1,6002026-07-14 HIGH 8.2 CVE-2026-14504 An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda … Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.4 CVE-2026-12988 The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the use… Mitigation only Fix from $1,6002026-07-14 MEDIUM 5.3 CVE-2026-11802 The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5… Mitigation only Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-62328 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user … Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-62191 OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers… Openclaw 2026.6.9+ Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-62194 OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers t… Openclaw 2026.6.9+ Fix from $1,9502026-07-13