Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 5.4
CVE-2026-19670

Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /au…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-55163

Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(ro…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.8
CVE-2026-48508

Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_p…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-61574

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpo…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-74906

SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the vi…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.3
CVE-2026-9816

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and arc…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-9859

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the …

Fix unknown
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.6
CVE-2026-71424

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} end…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-11817

This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-o…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-75480

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users …

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 7.5
CVE-2026-71518

Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to acces…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-44846

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user with the users.invite_user…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.9
CVE-2026-66792

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileg…

Fix unknown
Fix from $5,750 2026-08-17
Mattermost Server MEDIUM 6.3
CVE-2026-16048

Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles w…

Fix unknown
Fix from $4,000 2026-08-17
Mattermost Server MEDIUM 6.3
CVE-2026-10527

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which all…

Fix unknown
Fix from $4,000 2026-08-17
Mattermost Server MEDIUM 5.4
CVE-2026-16044

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive impo…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 7.0
CVE-2026-18674

On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlP…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-73059

stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requ…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-19726

The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contribu…

Fix unknown
Fix from $4,000 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-19598

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to,…

No fix yet
Fix from $5,750 2026-08-15
Unclassified HIGH 8.1
CVE-2026-19629

A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission o…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.1
CVE-2026-49989

CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.7
CVE-2026-72859

Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 …

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.8
CVE-2026-73049

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden a…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.8
CVE-2026-72831

The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiCo…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-73841

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go an…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-73305

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking app…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.7
CVE-2026-72672

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data …

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-72673

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properl…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.1
CVE-2026-72643

Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to…

No fix yet
Fix from $4,900 2026-08-13