Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 5.3
CVE-2026-54398

An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or at…

Patch available
Fix from $1,600 2026-06-12
Openclaw MEDIUM 6.5
CVE-2026-53834

OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to sk…

Fix: 2026.4.27+
Fix from $1,600 2026-06-12
Openclaw HIGH 8.8
CVE-2026-53828

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner…

Fix: 2026.5.6+
Fix from $1,950 2026-06-12
Unclassified MEDIUM 6.4
CVE-2026-53521

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /s…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified HIGH 7.1
CVE-2026-47120

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-49397

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private …

Mitigation only
Fix from $1,600 2026-06-12
Unclassified HIGH 7.7
CVE-2026-46717

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's d…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified MEDIUM 6.1
CVE-2026-54397

A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form data…

Patch available
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-54362

An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view galaxies that should not have…

Patch available
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.1
CVE-2026-54357

An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to si…

Patch available
Fix from $1,600 2026-06-12
Unclassified HIGH 7.5
CVE-2026-54358

An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same org…

Patch available
Fix from $1,950 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-42604

Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full …

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-50008

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-al…

Patch available
Fix from $1,600 2026-06-12
MariaDB MEDIUM 5.3
CVE-2026-44173

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11…

Fix: 10.6.26 / 10.11.17+
Fix from $1,600 2026-06-12
Mattermost Server HIGH 7.2
CVE-2026-6739

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patchin…

Fix: 10.11.17 / 11.5.5+
Fix from $1,950 2026-06-12
Mattermost Server HIGH 8.8
CVE-2026-7387

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authoriz…

Fix: 10.11.17 / 11.5.5+
Fix from $1,950 2026-06-12
Chromadb HIGH 8.8
CVE-2026-45831

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a…

Fix: after 1.5.9
Fix from $1,950 2026-06-12
Nuxt HIGH 8.2
CVE-2026-53721

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule m…

Fix: 3.21.7 / 4.4.7+
Fix from $1,950 2026-06-12
Unclassified HIGH 7.1
CVE-2026-47195

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level permissions on the invoking me…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified MEDIUM 6.5
CVE-2026-47238

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subt…

Mitigation only
Fix from $1,600 2026-06-11
Openclaw HIGH 8.8
CVE-2026-53807

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip com…

Fix: 2026.5.6+
Fix from $1,950 2026-06-11
Openclaw MEDIUM 6.5
CVE-2026-53808

OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply:…

Fix: 2026.5.6+
Fix from $1,600 2026-06-11
Unclassified HIGH 8.8
CVE-2026-46519

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes thr…

Mitigation only
Fix from $1,950 2026-06-11
GitLab MEDIUM 5.4
CVE-2026-6269

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un…

Fix: 18.10.8 / 18.11.5+
Fix from $1,600 2026-06-11
Imagemagick MEDIUM 5.5
CVE-2026-49219

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect…

Fix: 6.9.13-48 / 7.1.2-24+
Fix from $1,600 2026-06-10
Unclassified HIGH 8.1
CVE-2026-53738

Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers wi…

Mitigation only
Fix from $1,950 2026-06-10
Pan Os HIGH 7.2
CVE-2026-0272

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Int…

Fix: 10.2.7 / 10.2.10+
Fix from $1,950 2026-06-10
Unclassified HIGH 7.7
CVE-2026-49823

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…

Patch available
Fix from $1,950 2026-06-10
Unclassified HIGH 8.5
CVE-2026-49824

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…

Patch available
Fix from $1,950 2026-06-10
Erlang\/otp MEDIUM 6.5
CVE-2026-48860

Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-ov…

Fix: 11.2.12.9 / 11.6.0.2+
Fix from $1,600 2026-06-10