Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Animate HIGH 7.7
CVE-2026-48348

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exp…

Fix: 23.0.16 / 24.0.14+
Fix from $1,950 2026-07-14
Commerce MEDIUM 5.9
CVE-2026-47998

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi…

Fix: 1.21.0+
Fix from $1,600 2026-07-14
Commerce HIGH 8.2
CVE-2026-47984

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi…

Fix: 1.21.0+
Fix from $1,950 2026-07-14
Commerce HIGH 8.6
CVE-2026-47988

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi…

Fix: 1.21.0+
Fix from $1,950 2026-07-14
Commerce MEDIUM 6.8
CVE-2026-47996EPSS 20%

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker coul…

Fix: 1.21.0+
Fix from $1,600 2026-07-14
Commerce MEDIUM 5.9
CVE-2026-47997EPSS 9%

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi…

Fix: 1.21.0+
Fix from $1,600 2026-07-14
.net HIGH 8.8
CVE-2026-47303

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

Fix: 8.0.29 / 9.0.18+
Fix from $1,950 2026-07-14
Symfony HIGH 8.2
CVE-2026-45075

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGrant…

Fix: 7.4.12 / 8.0.12+
Fix from $1,950 2026-07-14
Devolutions Server HIGH 7.1
CVE-2026-15641

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user t…

Fix: 2026.1.23.0 / 2026.2.12.0+
Fix from $1,950 2026-07-14
Unclassified HIGH 7.3
CVE-2026-9127

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can all…

Mitigation only
Fix from $1,950 2026-07-14
Openclaw HIGH 8.3
CVE-2026-62196

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowl…

Fix: 2026.6.6+
Fix from $1,950 2026-07-13
Openclaw MEDIUM 5.4
CVE-2026-62198

OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to per…

Fix: 2026.6.6+
Fix from $1,600 2026-07-13
Openclaw HIGH 8.8
CVE-2026-62190

OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or pe…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw HIGH 7.1
CVE-2026-62191

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw HIGH 8.1
CVE-2026-62192

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to …

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw MEDIUM 6.5
CVE-2026-62193

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) …

Fix: 2026.6.9+
Fix from $1,600 2026-07-13
Openclaw HIGH 7.6
CVE-2026-62186

OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust cal…

Fix: 2026.6.8+
Fix from $1,950 2026-07-13
Openclaw\/feishu HIGH 8.1
CVE-2026-62187

OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configur…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw\/feishu HIGH 8.1
CVE-2026-62188

OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could i…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.5
CVE-2026-58408

ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admin/export UI and exfiltrate th…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.5
CVE-2026-62147

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was e…

Mitigation only
Fix from $1,600 2026-07-13
Mattermost Server MEDIUM 6.5
CVE-2026-10106

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches th…

Fix: 10.11.20 / 11.6.5+
Fix from $1,600 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15541

A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of…

Patch available
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15507

A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the compone…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 5.4
CVE-2026-56252

Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scop…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified HIGH 8.8
CVE-2026-1359

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Mitigation only
Fix from $1,950 2026-07-11
Rabbitmq Server HIGH 8.8
CVE-2026-57215

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to …

Fix: 4.2.6+
Fix from $1,950 2026-07-10
Rabbitmq Server MEDIUM 6.5
CVE-2026-57217

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic wr…

Fix: 4.2.6+
Fix from $1,600 2026-07-10
Rabbitmq Server MEDIUM 6.5
CVE-2026-57218

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth …

Fix: 4.2.6+
Fix from $1,600 2026-07-10
Snipe It MEDIUM 5.7
CVE-2026-55475

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid A…

Fix: 8.6.1+
Fix from $1,600 2026-07-10