Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-25440 Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions. Mitigation only Fix from $1,6002026-06-15 MEDIUM 6.3 CVE-2025-68049 Subscriber Broken Access Control in bunny.net <= 2.3.6 versions. Mitigation only Fix from $1,6002026-06-15 MEDIUM 6.5 CVE-2025-69332 Subscriber Broken Access Control in Bookify <= 1.1.1 versions. Mitigation only Fix from $1,6002026-06-15 CRITICAL 9.8 CVE-2026-38329 Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.p… Mitigation only Fix from $2,3002026-06-15 HIGH 7.1 CVE-2026-5230 Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Con… Mitigation only Fix from $1,9502026-06-15 MEDIUM 6.5 CVE-2026-48969 Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions. Mitigation only Fix from $1,6002026-06-15 MEDIUM 6.5 CVE-2025-64215 Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issu… Mitigation only Fix from $1,6002026-06-15 HIGH 8.6 CVE-2026-34024 The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. A… Mitigation only Fix from $1,9502026-06-15 MEDIUM 6.6 CVE-2026-53820 OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated call… Openclaw 2026.5.12+ Fix from $1,6002026-06-12 HIGH 8.8 CVE-2026-53821 OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization … Openclaw 2026.5.18+ Fix from $1,9502026-06-12 HIGH 7.1 CVE-2026-47120 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem… Mitigation only Fix from $1,9502026-06-12 HIGH 7.1 CVE-2026-48119 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authent… Mitigation only Fix from $1,9502026-06-12 CRITICAL 9.9 CVE-2026-46716 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem… Mitigation only Fix from $2,3002026-06-12 MEDIUM 5.3 CVE-2026-45085 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l… Discourse 2026.1.0 / 2026.1.4+ Fix from $1,6002026-06-12 HIGH 7.8 CVE-2026-42851 Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a d… Kitty 0.47.0+ Fix from $1,9502026-06-12 HIGH 7.5 CVE-2026-50108 The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the l… Mitigation only Fix from $1,9502026-06-12 MEDIUM 5.3 CVE-2026-50244 The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account … Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.1 CVE-2026-10715 Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user… Patch available Fix from $1,6002026-06-12 MEDIUM 6.9 CVE-2026-50026 Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unau… Mitigation only Fix from $1,6002026-06-12 MEDIUM 6.5 CVE-2026-50084 The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an inst… Cloud Production Api No fix yet Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-44975 Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users i… Mitigation only Fix from $1,6002026-06-12 HIGH 8.1 CVE-2026-7368 The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credent… Mitigation only Fix from $1,9502026-06-12 HIGH 7.2 CVE-2026-47197 Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can use the bot to moderate user… Mitigation only Fix from $1,9502026-06-12 MEDIUM 6.6 CVE-2026-53818 OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only… Openclaw 2026.4.24+ Fix from $1,6002026-06-11 MEDIUM 6.5 CVE-2026-53815 OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust cal… Openclaw 2026.5.19+ Fix from $1,6002026-06-11 HIGH 7.2 CVE-2026-53816 OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec … Openclaw 2026.5.18+ Fix from $1,9502026-06-11 HIGH 7.2 CVE-2026-47163 Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any guild member who can invoke sl… Mitigation only Fix from $1,9502026-06-11 CRITICAL 9.4 CVE-2026-4764 A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user wit… Mitigation only Fix from $2,3002026-06-11 MEDIUM 5.4 CVE-2023-25969 Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control S… Mitigation only Fix from $1,6002026-06-11 MEDIUM 5.4 CVE-2022-45813 Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels… Mitigation only Fix from $1,6002026-06-11