Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.4 CVE-2026-18709 An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepa… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-69113 Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-70340 Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. Azure Cyclecloud No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-65806 Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. Azure Cyclecloud No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-62915 Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. Exchange Server 15.02.2562.046+ Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-61936 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-59113 Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. Visual Studio Code No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-40375 Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. Dynamics 365 Business Central 2024 26.0.50788 / 27.0.50789+ Fix from $4,0002026-08-11 HIGH 7.1 CVE-2026-48495 TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trus… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-42142 TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate worksp… No fix yet Fix from $4,9002026-08-11 HIGH 8.6 CVE-2026-19539 Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated use… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.3 CVE-2026-73140 Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal commen… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.3 CVE-2026-73155 Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users … No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-14548 The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing an… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-58243 SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to exe… No fix yet Fix from $4,9002026-08-11 HIGH 7.3 CVE-2026-44764 Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted … No fix yet Fix from $4,9002026-08-11 HIGH 7.3 CVE-2026-44765 Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.9 CVE-2026-58237 WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit t… No fix yet Fix from $4,0002026-08-11 HIGH 8.7 CVE-2025-30237 The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certa… No fix yet Fix from $4,9002026-08-10 MEDIUM 5.4 CVE-2026-72918 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.… No fix yet Fix from $4,0002026-08-10 HIGH 7.1 CVE-2026-72910 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job… No fix yet Fix from $4,9002026-08-10 HIGH 8.5 CVE-2026-18947 A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a spec… No fix yet Fix from $4,9002026-08-10 HIGH 8.8 CVE-2026-72883 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.9 CVE-2026-72876 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getA… No fix yet Fix from $5,7502026-08-10 HIGH 8.2 CVE-2026-14886 Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated call… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.9 CVE-2026-72864 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/serve… No fix yet Fix from $5,7502026-08-10 HIGH 8.8 CVE-2026-72866 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validat… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.9 CVE-2026-72868 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the acce… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72863 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au… No fix yet Fix from $5,7502026-08-10 HIGH 7.5 CVE-2026-71962 Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that … No fix yet Fix from $4,9002026-08-10