Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Internet MEDIUM 5.5
CVE-2026-21036

Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.

Fix: 30.0.0.39+
Fix from $1,600 2026-06-05
Android HIGH 7.8
CVE-2026-21031

Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required f…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified MEDIUM 5.4
CVE-2026-42547

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users…

Mitigation only
Fix from $1,600 2026-06-04
Unclassified HIGH 8.6
CVE-2026-41235

Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell li…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified MEDIUM 6.3
CVE-2026-10815

A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown …

Mitigation only
Fix from $1,600 2026-06-04
Misp MEDIUM 6.5
CVE-2026-10860

A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to …

Fix: 2.5.39+
Fix from $1,600 2026-06-04
Unclassified CRITICAL 9.9
CVE-2026-41283

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which…

Mitigation only
Fix from $2,300 2026-06-04
T Mac Plus HIGH 7.4
CVE-2025-14774

Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Mitigation only
Fix from $1,950 2026-06-03
Librechat HIGH 8.1
CVE-2026-44654

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete f…

Fix: 0.8.5+
Fix from $1,950 2026-06-02
Alf CRITICAL 9.1
CVE-2026-35482

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox esca…

Fix: 2.0-M5-2606+
Fix from $2,300 2026-06-02
Prefect HIGH 7.5
CVE-2026-3514

In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health …

Fix: 3.6.22+
Fix from $1,950 2026-06-02
Android HIGH 7.8
CVE-2025-32348

In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privi…

Mitigation only
Fix from $1,950 2026-06-01
Capsule CRITICAL 9.1
CVE-2026-22872

Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantR…

Fix: 0.13.0+
Fix from $2,300 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10211

A vulnerability was determined in AstrBotDevs AstrBot 4.23.6. Affected by this issue is the function _normalize_rw_path of the file astrbot/core/tool…

Mitigation only
Fix from $1,600 2026-06-01
Teamcity MEDIUM 6.5
CVE-2026-49376

In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

Fix: 2026.1+
Fix from $1,600 2026-05-29
Cli CRITICAL 9.1
CVE-2026-48501

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF …

Fix: 2.93.0+
Fix from $2,300 2026-05-29
Openclaw MEDIUM 6.5
CVE-2026-35673

OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked t…

Fix: 2026.4.29+
Fix from $1,600 2026-05-29
Openclaw HIGH 8.8
CVE-2026-35674

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged comma…

Fix: 2026.5.18+
Fix from $1,950 2026-05-29
Openclaw MEDIUM 5.4
CVE-2026-34507

OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowF…

Fix: 2026.4.29+
Fix from $1,600 2026-05-29
Unclassified HIGH 7.1
CVE-2026-9808

An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured wi…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified MEDIUM 5.3
CVE-2026-49299

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined polic…

Mitigation only
Fix from $1,600 2026-05-28
Portainer HIGH 8.5
CVE-2026-44850

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…

Fix: 2.33.8 / 2.39.1+
Fix from $1,950 2026-05-28
Portainer HIGH 8.1
CVE-2026-44882

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…

Fix: 2.33.8+
Fix from $1,950 2026-05-28
Public Sector Financials HIGH 7.7
CVE-2026-46823

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versio…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
Unclassified MEDIUM 5.3
CVE-2026-42070

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in MantisBT allows users having update…

Patch available
Fix from $1,600 2026-05-28
Keystone HIGH 8.1
CVE-2026-44394

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's…

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-28
Unclassified HIGH 7.1
CVE-2026-45042

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows cop…

Mitigation only
Fix from $1,950 2026-05-28
Keystone HIGH 8.8
CVE-2026-42998

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user …

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-28
Keystone HIGH 8.8
CVE-2026-42999

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON re…

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-28
Keystone HIGH 8.8
CVE-2026-43000

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker wi…

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-28