Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Kirby MEDIUM 6.5
CVE-2026-40099

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content…

Fix: 4.9.0 / 5.4.0+
Fix from $1,600 2026-04-24
Kirby HIGH 8.8
CVE-2026-41325

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content…

Fix: 4.9.0 / 5.4.0+
Fix from $1,950 2026-04-24
Openclaw MEDIUM 5.4
CVE-2026-41348

OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths that fail to enforce group D…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw HIGH 8.8
CVE-2026-41344

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scoped gateway callers to persist…

Fix: 2026.3.28+
Fix from $1,950 2026-04-23
Openclaw MEDIUM 6.5
CVE-2026-41908

OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without op…

Fix: 2026.4.20+
Fix from $1,600 2026-04-23
Openclaw MEDIUM 5.4
CVE-2026-41909

OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allows limited-scope sessions to …

Fix: 2026.4.20+
Fix from $1,600 2026-04-23
Froxlor MEDIUM 5.0
CVE-2026-41232

Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full emai…

Fix: 2.3.6+
Fix from $1,600 2026-04-23
Froxlor MEDIUM 5.4
CVE-2026-41233

Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user inpu…

Fix: 2.3.6+
Fix from $1,600 2026-04-23
Helm Charts MEDIUM 5.0
CVE-2026-41131

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with cach…

Fix: 0.3.1 / 1.14.1+
Fix from $1,600 2026-04-22
Clearancekit HIGH 7.1
CVE-2026-40599

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats …

Fix: 5.0.5+
Fix from $1,950 2026-04-21
Unclassified HIGH 7.1
CVE-2026-41189

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through `ThreadPolicy::…

Patch available
Fix from $1,950 2026-04-21
Unclassified HIGH 7.1
CVE-2026-41190

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, direc…

Patch available
Fix from $1,950 2026-04-21
Unclassified HIGH 7.1
CVE-2026-41191

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave()` persists `chat_start_new`…

Patch available
Fix from $1,950 2026-04-21
Oauth2 Proxy MEDIUM 6.8
CVE-2026-40574

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy …

Fix: 7.15.2+
Fix from $1,600 2026-04-21
Unclassified MEDIUM 6.6
CVE-2026-26274

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox securit…

Mitigation only
Fix from $1,600 2026-04-21
Openclaw HIGH 8.8
CVE-2026-41303

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows non-approvers to resolve pendi…

Fix: 2026.3.28+
Fix from $1,950 2026-04-21
Nginx Ui HIGH 8.1
CVE-2026-33031

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously iss…

Fix: 2.3.4+
Fix from $1,950 2026-04-20
Fudo Enterprise MEDIUM 6.5
CVE-2025-13480

Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only resources via improperly protec…

Fix: 5.6.3+
Fix from $1,600 2026-04-20
Skymec It Manager HIGH 7.8
CVE-2026-39454

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A …

Fix: after 2024.005.10a
Fix from $1,950 2026-04-20
Airflow HIGH 7.5
CVE-2026-32228

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that …

Fix: 3.2.0+
Fix from $1,950 2026-04-18
Movary HIGH 8.8
CVE-2026-40350

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the use…

Fix: 0.71.1+
Fix from $1,950 2026-04-18
Zrok MEDIUM 5.3
CVE-2026-40304

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contai…

Fix: 2.0.1+
Fix from $1,600 2026-04-17
Nextjs Auth0 MEDIUM 5.4
CVE-2026-40155

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requ…

Fix: 4.18.0+
Fix from $1,600 2026-04-17
Openharness MEDIUM 5.5
CVE-2026-40515

OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete p…

Fix: 2026-04-11+
Fix from $1,600 2026-04-17
Unclassified MEDIUM 5.3
CVE-2026-24749

The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rend…

Mitigation only
Fix from $1,600 2026-04-16
Istio MEDIUM 5.4
CVE-2026-39350

Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 through 1.28.5, 1.29.0, and 1.29.1,…

Fix: 1.27.9 / 1.28.6+
Fix from $1,600 2026-04-15
Apostrophecms MEDIUM 5.3
CVE-2026-33888

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the get…

Fix: 4.29.0+
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.4
CVE-2026-6383

A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly truncates subresource names,…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified HIGH 8.4
CVE-2026-4857

IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticate…

Mitigation only
Fix from $1,950 2026-04-15
Velociraptor CRITICAL 9.1
CVE-2026-6290

Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token…

Fix: 0.76.3+
Fix from $2,300 2026-04-15