Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-69146 MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs … Fix unknown Fix from $4,0002026-08-17 HIGH 7.1 CVE-2026-69148 MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion … Fix unknown Fix from $4,9002026-08-17 MEDIUM 5.4 CVE-2026-75108 Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe … Fix unknown Fix from $4,0002026-08-17 HIGH 7.1 CVE-2026-75109 Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrup… Fix unknown Fix from $4,9002026-08-17 HIGH 7.1 CVE-2026-54356 Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts an… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-63669 ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destinati… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.5 CVE-2026-73424 Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverle… Fix unknown Fix from $4,0002026-08-17 HIGH 8.8 CVE-2026-9771 The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler … Fix unknown Fix from $4,9002026-08-17 HIGH 8.1 CVE-2026-75051 In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible Fix unknown Fix from $4,9002026-08-17 HIGH 8.1 CVE-2026-75044 In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary enti… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-75049 In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creat… Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.1 CVE-2026-64866 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPas… Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.3 CVE-2026-53960 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post conte… Fix unknown Fix from $4,0002026-08-17 HIGH 7.5 CVE-2026-16471 Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. Thi… Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-16467 Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. T… Fix unknown Fix from $4,9002026-08-17 HIGH 7.7 CVE-2026-74869 stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumer… Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-17087 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to,… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-19728 The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-upload… Fix unknown Fix from $4,9002026-08-16 CRITICAL 9.1 CVE-2026-18316 The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip… No fix yet Fix from $5,7502026-08-16 MEDIUM 5.3 CVE-2026-8840 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2… No fix yet Fix from $4,0002026-08-15 HIGH 8.1 CVE-2026-16772 In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting ful… No fix yet Fix from $4,9002026-08-14 MEDIUM 5.8 CVE-2026-73048 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifi… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.4 CVE-2026-72823 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method… No fix yet Fix from $4,0002026-08-14 CRITICAL 9.8 CVE-2026-72824 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-tog… No fix yet Fix from $5,7502026-08-14 HIGH 7.6 CVE-2026-72825 The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsCo… No fix yet Fix from $4,9002026-08-14 MEDIUM 6.5 CVE-2026-72812 SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to… No fix yet Fix from $4,0002026-08-14 HIGH 8.6 CVE-2026-72810 SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receiv… No fix yet Fix from $4,9002026-08-14 CRITICAL 9.0 CVE-2026-73842 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go ex… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.6 CVE-2026-73843 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-f… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.3 CVE-2026-73665 FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socke… No fix yet Fix from $5,7502026-08-13