Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 5.3
CVE-2026-55479

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkou…

Patch available
Fix from $1,600 2026-07-10
Snipe It HIGH 7.1
CVE-2026-55460

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.d…

Fix: 8.6.2+
Fix from $1,950 2026-07-10
Unclassified HIGH 7.4
CVE-2026-55672

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device …

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 8.6
CVE-2026-55638

9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /co…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 7.1
CVE-2026-39903

Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/A…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 8.1
CVE-2026-22659

FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated moderators to perform unauth…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-40452

Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value dat…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15332

A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of t…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-5069

The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-15320

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pi…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15318

A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqt…

Mitigation only
Fix from $1,600 2026-07-10
Open Webui MEDIUM 5.4
CVE-2026-59227

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required on…

Fix: 0.10.0+
Fix from $1,600 2026-07-09
Open Webui MEDIUM 5.4
CVE-2026-59212

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_knowledge_file_access only ch…

Patch available
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-61474

An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to add attributes to submit a sha…

Patch available
Fix from $1,600 2026-07-09
Chrome HIGH 8.8
CVE-2026-15125

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox v…

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.5
CVE-2026-58494

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory p…

Patch available
Fix from $1,600 2026-07-08
Nats Server MEDIUM 5.4
CVE-2026-58211

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be regi…

Fix: 2.12.12 / 2.14.3+
Fix from $1,600 2026-07-08
Opencti HIGH 7.1
CVE-2026-35210

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vul…

Fix: 7.260326.0+
Fix from $1,950 2026-07-08
Opencti MEDIUM 6.5
CVE-2026-35211

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exp…

Fix: 7.260401.0+
Fix from $1,600 2026-07-08
Moveit Transfer HIGH 8.8
CVE-2026-8800

Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 202…

Fix: 2025.0.7 / 2025.1.3+
Fix from $1,950 2026-07-08
Nats Server MEDIUM 6.5
CVE-2026-58254

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destinati…

Fix: 2.12.8 / 2.14.3+
Fix from $1,600 2026-07-08
Unclassified HIGH 8.1
CVE-2026-54652

Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the…

Patch available
Fix from $1,950 2026-07-08
Unclassified MEDIUM 5.3
CVE-2026-60125

MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not enforce the per-organisation mo…

Patch available
Fix from $1,600 2026-07-08
N8n MEDIUM 5.4
CVE-2026-56775

n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-…

Fix: 1.123.55 / 2.25.7+
Fix from $1,600 2026-07-08
N8n HIGH 7.4
CVE-2026-56776

n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint, which authorizes…

Fix: 1.123.55 / 2.25.7+
Fix from $1,950 2026-07-08
N8n MEDIUM 6.4
CVE-2026-56778

n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, which authorizes access using…

Fix: 2.25.7 / 2.26.2+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.5
CVE-2026-56220

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows read-only org members to insert…

Mitigation only
Fix from $1,600 2026-07-08
Data Domain Operating System HIGH 8.8
CVE-2026-56086

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug…

Fix: 7.13.1.80 / 8.3.1.40+
Fix from $1,950 2026-07-08
Coder HIGH 8.2
CVE-2026-55428

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tail…

Fix: 2.29.17 / 2.32.7+
Fix from $1,950 2026-07-08
Graphql Engine MEDIUM 5.9
CVE-2026-54698

Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table compu…

Fix: after 2.49.2
Fix from $1,600 2026-07-07