Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 6.9
CVE-2026-53935

Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the abil…

Patch available
Fix from $1,600 2026-07-07
Unclassified HIGH 8.7
CVE-2026-50529

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns …

Patch available
Fix from $1,950 2026-07-07
Coder MEDIUM 5.4
CVE-2026-55435

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.…

Fix: 2.32.7 / 2.33.8+
Fix from $1,600 2026-07-07
Unclassified MEDIUM 5.9
CVE-2026-12352

This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.

Mitigation only
Fix from $1,600 2026-07-07
Unclassified CRITICAL 9.9
CVE-2026-34047

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket boots…

Patch available
Fix from $2,300 2026-07-07
Unclassified MEDIUM 5.3
CVE-2026-53642

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Require Email Confirmation" setti…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.5
CVE-2026-32718

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation …

Patch available
Fix from $1,600 2026-07-06
Traefik HIGH 8.5
CVE-2026-54765

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve tw…

Fix: 3.7.6+
Fix from $1,950 2026-07-06
Unclassified HIGH 7.7
CVE-2026-42331

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an …

Mitigation only
Fix from $1,950 2026-07-06
Devolutions Server HIGH 8.8
CVE-2026-14536

Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credential…

Fix: after 2026.2.9.0
Fix from $1,950 2026-07-06
Unclassified MEDIUM 6.3
CVE-2026-14716

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. Impacted is the function MethodRouter.Handle of the file i…

Mitigation only
Fix from $1,600 2026-07-05
Unclassified HIGH 8.9
CVE-2026-58424

Permanent Fork PR Workflow Approval Gate Bypass

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 8.1
CVE-2026-28744

Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 8.8
CVE-2026-27775

Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-…

Patch available
Fix from $1,950 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-27780

Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass b…

Patch available
Fix from $2,300 2026-07-03
Unclassified HIGH 8.1
CVE-2026-28699

Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 7.1
CVE-2026-28740

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lac…

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 8.5
CVE-2026-26231

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user c…

Patch available
Fix from $1,950 2026-07-03
Exchange Online HIGH 8.8
CVE-2026-54998

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-07-02
Flowmon HIGH 7.3
CVE-2026-8079

In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request dur…

Fix: 12.5.9 / 13.0.11+
Fix from $1,950 2026-07-02
Unifi Network Application HIGH 7.5
CVE-2026-56842

A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Netwo…

Fix: 10.4.57+
Fix from $1,950 2026-07-02
Enterprise Server MEDIUM 5.0
CVE-2026-14340

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App instal…

Fix: 3.16.20 / 3.17.17+
Fix from $1,600 2026-07-01
Containerd CRITICAL 9.6
CVE-2026-53492

containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Devic…

Fix: 2.1.9 / 2.2.5+
Fix from $2,300 2026-07-01
Endpoint Security MEDIUM 5.3
CVE-2026-56152

Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrai…

Fix: 8.19.13 / 9.2.7+
Fix from $1,600 2026-07-01
Mycomplianceoffice MEDIUM 6.5
CVE-2026-53902

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated u…

Mitigation only
Fix from $1,600 2026-07-01
Mycomplianceoffice HIGH 7.1
CVE-2026-53905

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authe…

Mitigation only
Fix from $1,950 2026-07-01
Langflow CRITICAL 9.8
CVE-2026-7663

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t…

Fix: 1.10.0+
Fix from $2,300 2026-06-30
Campaign CRITICAL 10.0
CVE-2026-48286

Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbi…

Fix: after 7.4.3
Fix from $2,300 2026-06-30
Unclassified HIGH 8.1
CVE-2026-57950

ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers…

Patch available
Fix from $1,950 2026-06-29
Mythic MEDIUM 6.5
CVE-2026-57951

Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypasse…

Fix: 3.4.0.60+
Fix from $1,600 2026-06-29