Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.8 CVE-2026-72799 SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPa… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72800 SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retr… No fix yet Fix from $4,0002026-08-12 HIGH 8.6 CVE-2026-72789 SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous re… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72790 SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata wi… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72791 SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in th… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.9 CVE-2026-63300 An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_c… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-19656 ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privil… No fix yet Fix from $5,7502026-08-12 HIGH 7.1 CVE-2026-16494 GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.4 CVE-2026-73296 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and… No fix yet Fix from $5,7502026-08-12 MEDIUM 5.9 CVE-2026-69107 An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-68971 Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finis… Airflow 3.3.1+ Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-68758 A low-privileged authenticated user may access restricted support information under specific conditions. No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-73405 An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) strea… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-73287 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/s… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-73265 RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadP… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-68754 A repository publisher without delete permission may modify protected package content under specific conditions. No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-68753 An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-66375 A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. No fix yet Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-66377 An unauthenticated user may access restricted repository information under specific conditions. No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-47233 Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modu… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-47226 Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can… No fix yet Fix from $4,0002026-08-12 HIGH 7.0 CVE-2026-53996 NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to i… No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-18789 The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated atta… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-18035 The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attacker… No fix yet Fix from $4,0002026-08-12 HIGH 8.2 CVE-2026-64954 Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT… No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-73249 calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/… No fix yet Fix from $4,9002026-08-11 HIGH 8.2 CVE-2026-48763 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{b… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-15606 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-69115 OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-only management API endpoints … No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-18704 An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against co… No fix yet Fix from $4,0002026-08-11