Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified HIGH 7.1
CVE-2026-72630

Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to m…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.1
CVE-2026-73652

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-58443

Public-only repository tokens can update private PR head branches

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-57897

Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.1
CVE-2026-58416

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-58427

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-55987

OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-56443

Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.1
CVE-2026-24791

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-70463

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when sp…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.4
CVE-2026-70452

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS …

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-53786

rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supp…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.8
CVE-2026-49473

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by ma…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-71193

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the targe…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 7.1
CVE-2026-73499

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permissi…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72788

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator wo…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72792

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts f…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63296

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When m…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63297

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target proj…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-62420

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project ins…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.5
CVE-2026-15423

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under …

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.1
CVE-2026-73286

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request he…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.1
CVE-2026-73289

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifie…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-73290

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/ac…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-73265

RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadP…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2026-73285

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTF…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.7
CVE-2026-18171

Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge g…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-47230

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same ro…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.1
CVE-2026-47231

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking tha…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-47227

Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, ……

No fix yet
Fix from $4,000 2026-08-12