Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.7 CVE-2026-54322 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organization … Mitigation only Fix from $1,9502026-06-23 MEDIUM 6.5 CVE-2026-54019 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI added collection-level … Open Webui 0.9.6+ Fix from $1,6002026-06-23 HIGH 8.3 CVE-2026-54010 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated u… Open Webui 0.9.6+ Fix from $1,9502026-06-23 HIGH 7.1 CVE-2026-54012 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can cre… Open Webui 0.9.6+ Fix from $1,9502026-06-23 HIGH 8.8 CVE-2026-56115 Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actio… Bootimus after 0.1.70 Fix from $1,9502026-06-23 MEDIUM 6.5 CVE-2026-56695 OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load… Patch available Fix from $1,6002026-06-23 MEDIUM 5.4 CVE-2026-56696 OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controll… Patch available Fix from $1,6002026-06-23 MEDIUM 6.5 CVE-2026-56402 NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role auth… Patch available Fix from $1,6002026-06-23 CRITICAL 10.0 CVE-2026-27604 FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas… Mitigation only Fix from $2,3002026-06-23 MEDIUM 6.8 CVE-2026-10609 A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output d… Cluster Logging Operator Mitigation only Fix from $1,6002026-06-23 HIGH 7.1 CVE-2026-56280 Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel running… Mitigation only Fix from $1,9502026-06-22 MEDIUM 6.5 CVE-2026-48500 Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can con… Mitigation only Fix from $1,6002026-06-22 MEDIUM 6.9 CVE-2026-8934 A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthentica… Mitigation only Fix from $1,6002026-06-22 HIGH 8.2 CVE-2026-56104 Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user ses… Patch available Fix from $1,9502026-06-22 MEDIUM 5.4 CVE-2026-5139 Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{se… Mattermost Server 10.11.18 / 11.5.6+ Fix from $1,6002026-06-22 HIGH 8.8 CVE-2026-56424 MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/edita… Misp 2.5.42+ Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-56423 MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handle… Misp 2.5.42+ Fix from $1,9502026-06-22 HIGH 7.2 CVE-2026-44914 Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Per… Nifi 2.10.0+ Fix from $1,9502026-06-22 MEDIUM 5.3 CVE-2026-7859 The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated a… Mitigation only Fix from $1,6002026-06-22 HIGH 8.8 CVE-2026-56396 phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administ… Mitigation only Fix from $1,9502026-06-21 HIGH 7.5 CVE-2026-56341 AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPa… Mitigation only Fix from $1,9502026-06-20 HIGH 7.5 CVE-2026-11912 The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to… Mitigation only Fix from $1,9502026-06-20 MEDIUM 6.5 CVE-2026-12119 The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' sho… Mitigation only Fix from $1,6002026-06-20 MEDIUM 5.3 CVE-2026-56213 Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgRES… Mitigation only Fix from $1,6002026-06-20 CRITICAL 9.6 CVE-2026-48582 Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Exchange Online Mitigation only Fix from $2,3002026-06-19 HIGH 8.1 CVE-2026-49291 mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only O… Mitigation only Fix from $1,9502026-06-19 MEDIUM 5.3 CVE-2026-12238 The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. Th… No fix yet Fix from $1,6002026-06-19 HIGH 8.8 CVE-2026-49357 Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop appli… Patch available Fix from $1,9502026-06-19 MEDIUM 5.3 CVE-2026-3640 The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin reg… Mitigation only Fix from $1,6002026-06-19 MEDIUM 5.3 CVE-2026-6798 The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5… No fix yet Fix from $1,6002026-06-19