Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 5.4
CVE-2026-56694

NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fai…

Patch available
Fix from $1,600 2026-06-23
Unclassified CRITICAL 10.0
CVE-2026-27604

FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas…

Mitigation only
Fix from $2,300 2026-06-23
Flowise HIGH 7.7
CVE-2026-56268

Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parame…

Fix: 3.1.2+
Fix from $1,950 2026-06-22
Unclassified HIGH 8.7
CVE-2026-54281

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass vulnerability exists in @nestj…

Mitigation only
Fix from $1,950 2026-06-22
Qsnapper HIGH 7.1
CVE-2026-41048

Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like …

Fix: 1.3.3+
Fix from $1,950 2026-06-22
Qsnapper HIGH 7.1
CVE-2026-41049

Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus…

Fix: 1.3.3+
Fix from $1,950 2026-06-22
Misp HIGH 8.8
CVE-2026-56424

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/edita…

Fix: 2.5.42+
Fix from $1,950 2026-06-22
Nifi MEDIUM 6.3
CVE-2026-44911

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submi…

Fix: 2.10.0+
Fix from $1,600 2026-06-22
Litellm MEDIUM 6.3
CVE-2026-12797

A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_h…

Fix: after 1.82.5
Fix from $1,600 2026-06-21
Quarkus HIGH 7.5
CVE-2026-50559

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.…

Fix: 3.20.6.2 / 3.27.4.1+
Fix from $1,950 2026-06-19
Proxysql CRITICAL 10.0
CVE-2026-48772

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY U…

Fix: 3.0.9+
Fix from $2,300 2026-06-19
Unclassified HIGH 7.1
CVE-2026-48089

DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instance with one or more public ass…

Patch available
Fix from $1,950 2026-06-19
Apisix HIGH 8.1
CVE-2026-47339

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authentica…

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Unclassified MEDIUM 5.5
CVE-2026-56074

PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to …

Mitigation only
Fix from $1,600 2026-06-18
Unclassified HIGH 8.8
CVE-2026-56075

PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding …

Mitigation only
Fix from $1,950 2026-06-18
Unclassified MEDIUM 5.9
CVE-2026-10741

Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-54803

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-48781

Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob int…

Patch available
Fix from $2,300 2026-06-17
Dolphinscheduler MEDIUM 6.5
CVE-2026-42357

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to acces…

Fix: 3.4.2+
Fix from $1,600 2026-06-17
Dolphinscheduler CRITICAL 9.8
CVE-2026-32966

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache …

Fix: 3.4.2+
Fix from $2,300 2026-06-17
Dolphinscheduler CRITICAL 9.1
CVE-2026-32967

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before…

Fix: 3.4.2+
Fix from $2,300 2026-06-17
Langgraph Sdk CRITICAL 9.1
CVE-2026-48776

LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versio…

Fix: 0.3.15+
Fix from $2,300 2026-06-17
Openclaw MEDIUM 5.4
CVE-2026-53860

OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through con…

Fix: 2026.5.7+
Fix from $1,600 2026-06-16
Openclaw HIGH 8.3
CVE-2026-53853

OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments …

Fix: 2026.5.12+
Fix from $1,950 2026-06-16
Openclaw MEDIUM 6.5
CVE-2026-53854

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit…

Fix: 2026.4.25+
Fix from $1,600 2026-06-16
Openclaw HIGH 8.1
CVE-2026-53855

OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell po…

Fix: 2026.4.2+
Fix from $1,950 2026-06-16
Unclassified MEDIUM 6.5
CVE-2026-5149

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submissio…

Mitigation only
Fix from $1,600 2026-06-16
Unclassified HIGH 7.5
CVE-2026-47777

Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts …

Patch available
Fix from $1,950 2026-06-15
Unclassified HIGH 8.8
CVE-2016-20075

WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, au…

No fix yet
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2026-34023

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability in the WebSocket communicati…

Mitigation only
Fix from $1,950 2026-06-15