Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Lxc MEDIUM 6.5
CVE-2026-39402

lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an…

Fix: 7.0.0+
Fix from $1,600 2026-05-05
Quarkus HIGH 8.2
CVE-2026-39852

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, …

Fix: 3.20.6.1 / 3.27.3.1+
Fix from $1,950 2026-05-05
Coredns HIGH 7.5
CVE-2026-33489

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone…

Fix: 1.14.3+
Fix from $1,950 2026-05-05
Openclaw HIGH 8.8
CVE-2026-43530

OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution that allow…

Fix: 2026.4.12+
Fix from $1,950 2026-05-05
Openclaw HIGH 7.7
CVE-2026-42438

OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media attachment read helper that allow…

Patch available
Fix from $1,950 2026-05-05
Unclassified HIGH 8.8
CVE-2026-42434

OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying h…

Patch available
Fix from $1,950 2026-05-05
Nginx Ui MEDIUM 6.5
CVE-2026-42220

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sens…

Fix: 2.3.8+
Fix from $1,600 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Qca7005 Firmware CRITICAL 9.8
CVE-2026-25293

Buffer overflow due to incorrect authorization in PLC FW

No fix yet
Fix from $2,300 2026-05-04
Prosody MEDIUM 6.5
CVE-2026-43504

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles …

Fix: 0.12.6 / 13.0.5+
Fix from $1,600 2026-05-01
Keystone HIGH 8.0
CVE-2026-43001

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-typ…

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-01
Traefik MEDIUM 6.4
CVE-2026-41174

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik'…

Fix: 2.11.43 / 3.6.14+
Fix from $1,600 2026-04-30
Identityiq HIGH 8.8
CVE-2026-5712

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit t…

Fix: 8.3+
Fix from $1,950 2026-04-29
Openclaw HIGH 8.1
CVE-2026-42431

OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of persistent browser profiles. …

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 7.8
CVE-2026-42432

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands witho…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 8.8
CVE-2026-42426

OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts operator.write scope instead of …

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 7.1
CVE-2026-42429

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that escalates identity-be…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 8.8
CVE-2026-42422

OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting tokens for unapproved roles. At…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 8.8
CVE-2026-41404

OpenClaw before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that allows operator.admin privile…

Fix: 2026.3.31+
Fix from $1,950 2026-04-28
Openclaw MEDIUM 5.4
CVE-2026-41381

OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attackers to bypass channel-level …

Fix: 2026.3.31+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-41375

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce…

Fix: 2026.3.28+
Fix from $1,600 2026-04-28
Openclaw HIGH 7.1
CVE-2026-41379

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class…

Fix: 2026.3.28+
Fix from $1,950 2026-04-28
Openclaw HIGH 8.5
CVE-2026-41371

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only s…

Fix: 2026.3.28+
Fix from $1,950 2026-04-28
Openclaw MEDIUM 5.0
CVE-2026-41367

OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions.…

Fix: 2026.3.28+
Fix from $1,600 2026-04-28
Unclassified CRITICAL 9.1
CVE-2026-41248

Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro c…

Mitigation only
Fix from $2,300 2026-04-24
Better Auth\/oauth Provider MEDIUM 6.5
CVE-2026-41427

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but…

Fix: 1.6.5+
Fix from $1,600 2026-04-24
Unclassified MEDIUM 5.4
CVE-2026-30368

A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integri…

Mitigation only
Fix from $1,600 2026-04-24
Codechecker CRITICAL 9.8
CVE-2026-25660

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs …

Fix: 6.27.4+
Fix from $2,300 2026-04-24
Dolphinscheduler HIGH 8.1
CVE-2026-23902

Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not…

Fix: 3.4.1+
Fix from $1,950 2026-04-24
Kyverno HIGH 7.7
CVE-2026-41068

Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalat…

Fix: 1.17.2+
Fix from $1,950 2026-04-24