Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.4 CVE-2022-42479 Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sol… Mitigation only Fix from $1,6002026-06-11 HIGH 7.2 CVE-2026-0272 A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Int… Pan Os 10.2.7 / 10.2.10+ Fix from $1,9502026-06-10 HIGH 7.7 CVE-2026-49821 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 HIGH 7.7 CVE-2026-49822 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 CRITICAL 9.8 CVE-2026-46614 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 HIGH 8.3 CVE-2026-46558 Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated… Plane 1.3.1+ Fix from $1,9502026-06-10 CRITICAL 9.1 CVE-2026-45550 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smo… Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-45552 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares … Mitigation only Fix from $2,3002026-06-10 HIGH 8.5 CVE-2026-45549 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/a… Mitigation only Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-11852 Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifa… Mitigation only Fix from $1,6002026-06-10 HIGH 7.5 CVE-2026-26237 A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthor… Qumagie 2.9.0+ Fix from $1,9502026-06-10 HIGH 8.7 CVE-2026-46518 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-sit… Openemr 8.0.0.1+ Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-49956 Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to ot… Patch available Fix from $1,6002026-06-09 CRITICAL 9.6 CVE-2026-47281 Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. Visual Studio Code 1.123.1+ Fix from $2,3002026-06-09 HIGH 8.1 CVE-2026-49948 Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POS… Patch available Fix from $1,9502026-06-09 MEDIUM 5.3 CVE-2026-47352 Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to f… Patch available Fix from $1,6002026-06-09 HIGH 8.7 CVE-2026-49741 Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via Dat… Patch available Fix from $1,9502026-06-09 HIGH 7.2 CVE-2026-47343 Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of … Patch available Fix from $1,9502026-06-09 HIGH 7.6 CVE-2026-47346 Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form … Patch available Fix from $1,9502026-06-09 MEDIUM 5.3 CVE-2026-47349 Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify.… Patch available Fix from $1,6002026-06-09 MEDIUM 5.3 CVE-2026-47350 Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions… Patch available Fix from $1,6002026-06-09 MEDIUM 5.3 CVE-2026-47351 Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to … Patch available Fix from $1,6002026-06-09 HIGH 7.6 CVE-2026-11607 Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without den… Patch available Fix from $1,9502026-06-09 MEDIUM 5.3 CVE-2026-4986 The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing una… Mitigation only Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-26236 A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthor… Qumagie 2.9.0+ Fix from $1,9502026-06-09 MEDIUM 6.6 CVE-2026-44754 The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permi… Mitigation only Fix from $1,6002026-06-09 HIGH 7.1 CVE-2026-44751 Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker to execute a report generation… Mitigation only Fix from $1,9502026-06-09 CRITICAL 9.8 CVE-2026-39910 STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to f… Mitigation only Fix from $2,3002026-06-08 HIGH 8.8 CVE-2026-46444 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assist… Flowise 3.1.2+ Fix from $1,9502026-06-08 MEDIUM 5.3 CVE-2026-8502 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all … Mitigation only Fix from $1,6002026-06-06