Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 5.9
CVE-2026-41470

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Sessi…

Mitigation only
Fix from $1,600 2026-05-19
Pro Cloud Server HIGH 8.8
CVE-2026-42096

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privi…

Fix: after 6.1.167
Fix from $1,950 2026-05-19
Open Webui HIGH 7.3
CVE-2026-44567

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the API does not properly valida…

Fix: 0.1.124+
Fix from $1,950 2026-05-15
Open Webui HIGH 8.8
CVE-2026-45672

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the /api/v1/utils/code/execute en…

Fix: 0.8.12+
Fix from $1,950 2026-05-15
Open Webui MEDIUM 5.4
CVE-2026-44564

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the ydoc:document:update Socket.IO…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui MEDIUM 6.5
CVE-2026-45339

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restri…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui MEDIUM 5.4
CVE-2026-44561

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the is_user_channel_member functio…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Unclassified MEDIUM 6.5
CVE-2026-46362

phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified HIGH 7.5
CVE-2026-46366

phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing …

Mitigation only
Fix from $1,950 2026-05-15
Unclassified HIGH 8.1
CVE-2026-44633

Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allow…

Mitigation only
Fix from $1,950 2026-05-14
Distribution MEDIUM 6.5
CVE-2026-41888

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag>…

Fix: 3.1.1+
Fix from $1,600 2026-05-14
Hatchet MEDIUM 6.5
CVE-2026-42572

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a missing authorization direct…

Fix: 0.83.39+
Fix from $1,600 2026-05-14
Unclassified HIGH 8.8
CVE-2025-15023

Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Au…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 7.1
CVE-2026-32991

Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.

Mitigation only
Fix from $1,950 2026-05-13
Misp HIGH 7.2
CVE-2026-44380

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key …

Fix: 2.5.37+
Fix from $1,950 2026-05-13
Ckan CRITICAL 9.1
CVE-2026-42032

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastor…

Fix: 2.10.10 / 2.11.5+
Fix from $2,300 2026-05-13
Vm2 CRITICAL 9.9
CVE-2026-43999

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (includi…

Fix: 3.11.0+
Fix from $2,300 2026-05-13
Next.js HIGH 7.5
CVE-2026-44573

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router …

Fix: 15.5.16 / 16.2.5+
Fix from $1,950 2026-05-13
Unclassified CRITICAL 9.9
CVE-2026-41050

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored…

Mitigation only
Fix from $2,300 2026-05-13
Gerrit MEDIUM 5.3
CVE-2026-2725

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permis…

Patch available
Fix from $1,600 2026-05-13
Unclassified HIGH 7.1
CVE-2026-45226

Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflow…

Patch available
Fix from $1,950 2026-05-12
Unclassified HIGH 8.1
CVE-2026-44260

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modific…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.9
CVE-2026-43948

wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a …

Mitigation only
Fix from $2,300 2026-05-12
Unclassified MEDIUM 5.7
CVE-2026-33570

PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational perm…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.3
CVE-2026-35555

PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of pro…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 8.2
CVE-2026-26289

PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information …

Mitigation only
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.0
CVE-2026-44221

ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific data…

Patch available
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-42889

Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebS…

Mitigation only
Fix from $2,300 2026-05-12
Commerce HIGH 7.5
CVE-2026-34645

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulne…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-05-12
Commerce HIGH 7.5
CVE-2026-34646

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulne…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-05-12