Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-31244 The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoi… Mem0 Mitigation only Fix from $1,6002026-05-12 CRITICAL 9.8 CVE-2026-26083 A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 throug… Fortisandbox 4.4.9 / 5.0.2+ Fix from $2,3002026-05-12 MEDIUM 5.3 CVE-2026-25431 Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects H… Mitigation only Fix from $1,6002026-05-12 MEDIUM 5.4 CVE-2026-45210 Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured Access Control Security Level… No fix yet Fix from $1,6002026-05-12 MEDIUM 5.3 CVE-2026-45212 Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting Incorrectly Configured Access… Mitigation only Fix from $1,6002026-05-12 MEDIUM 5.3 CVE-2026-6708 The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and includi… Mitigation only Fix from $1,6002026-05-12 MEDIUM 5.3 CVE-2026-5693 The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce… Mitigation only Fix from $1,6002026-05-12 HIGH 8.2 CVE-2026-39432 Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affect… Mitigation only Fix from $1,9502026-05-12 MEDIUM 5.4 CVE-2026-40132 Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker coul… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.3 CVE-2026-40133 Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify … Mitigation only Fix from $1,6002026-05-12 HIGH 7.7 CVE-2026-43885 WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.j… Patch available Fix from $1,9502026-05-11 MEDIUM 5.5 CVE-2026-20696 An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive … macOS 26.4+ Fix from $1,6002026-05-11 HIGH 7.1 CVE-2026-45001 OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to pro… Openclaw 2026.4.20+ Fix from $1,9502026-05-11 MEDIUM 5.3 CVE-2026-44994 OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that allows unauthenticated att… Openclaw 2026.4.22+ Fix from $1,6002026-05-11 MEDIUM 5.4 CVE-2026-43638 Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitr… Server 2026.4.1+ Fix from $1,6002026-05-11 CRITICAL 9.1 CVE-2026-43639 Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organizati… Server 2026.4.0+ Fix from $2,3002026-05-11 HIGH 7.5 CVE-2026-33357 In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x… Mitigation only Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-33359 In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable with… Mitigation only Fix from $1,9502026-05-11 CRITICAL 9.4 CVE-2026-42613 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and acc… Patch available Fix from $2,3002026-05-11 HIGH 8.8 CVE-2026-32658 Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access coul… Automation Platform 2.0.0.0+ Fix from $1,9502026-05-11 CRITICAL 9.8 CVE-2021-47932 WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts … Mitigation only Fix from $2,3002026-05-10 CRITICAL 9.4 CVE-2026-42569 phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access… Patch available Fix from $2,3002026-05-09 HIGH 7.5 CVE-2026-42461 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/template… Arcane 1.18.0+ Fix from $1,9502026-05-09 HIGH 8.3 CVE-2026-42297 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version… Argo Workflows 4.0.5+ Fix from $1,9502026-05-09 MEDIUM 6.5 CVE-2026-42069 Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by … Kirby 4.9.0 / 5.4.0+ Fix from $1,6002026-05-09 MEDIUM 6.5 CVE-2026-42137 Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not… Kirby 4.9.0 / 5.4.0+ Fix from $1,6002026-05-09 CRITICAL 9.3 CVE-2026-44125 SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthe… Mitigation only Fix from $2,3002026-05-08 HIGH 8.8 CVE-2026-39816 The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi… Nifi 2.9.0+ Fix from $1,9502026-05-08 HIGH 8.6 CVE-2026-8077 Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend lacks authorization controls,… Mitigation only Fix from $1,9502026-05-08 MEDIUM 5.3 CVE-2026-27416 Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affec… Mitigation only Fix from $1,6002026-05-07