Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified HIGH 8.1
CVE-2025-40897

An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enfor…

Mitigation only
Fix from $1,950 2026-04-15
Chamilo Lms HIGH 8.8
CVE-2026-40291

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in th…

Fix: after 1.11.38
Fix from $1,950 2026-04-14
Unclassified MEDIUM 5.4
CVE-2026-24069

Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application…

Mitigation only
Fix from $1,600 2026-04-14
Unclassified MEDIUM 6.8
CVE-2026-40191

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta-1f46165, ClearanceKit's End…

Mitigation only
Fix from $1,600 2026-04-10
Openclaw HIGH 8.1
CVE-2026-35653

OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers wit…

Fix: 2026.3.24+
Fix from $1,950 2026-04-10
Openclaw MEDIUM 6.5
CVE-2026-35657

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read sco…

Fix: 2026.3.25+
Fix from $1,600 2026-04-10
Systemd HIGH 7.3
CVE-2026-40224

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

Fix: 259.3+
Fix from $1,950 2026-04-10
Keystone MEDIUM 5.3
CVE-2026-33551

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create …

Fix: 26.1.1+
Fix from $1,600 2026-04-10
Unclassified MEDIUM 5.4
CVE-2026-2712

The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat…

Mitigation only
Fix from $1,600 2026-04-10
Openclaw HIGH 8.8
CVE-2026-35645

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a sy…

Fix: 2026.3.25+
Fix from $1,950 2026-04-09
Openclaw MEDIUM 6.5
CVE-2026-35635

OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse mu…

Fix: 2026.3.22+
Fix from $1,600 2026-04-09
Openclaw HIGH 8.1
CVE-2026-34512

OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authe…

Fix: 2026.3.25+
Fix from $1,950 2026-04-09
Pyload MEDIUM 5.4
CVE-2026-40071

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abo…

Fix: 2026-04-13+
Fix from $1,600 2026-04-09
Kibana MEDIUM 6.5
CVE-2026-33461

Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user with limited Fleet privileges …

Fix: 8.19.14 / 9.2.8+
Fix from $1,600 2026-04-08
Go HIGH 8.8
CVE-2026-27140

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer…

Fix: 1.25.9 / 1.26.2+
Fix from $1,950 2026-04-08
Churchcrm HIGH 8.1
CVE-2026-39331

ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper a…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Unclassified HIGH 7.1
CVE-2026-22682

OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling i…

Patch available
Fix from $1,950 2026-04-07
Pyload Ng MEDIUM 6.8
CVE-2026-35586

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_con…

Fix: after 0.5.0b3.dev96
Fix from $1,600 2026-04-07
Filebrowser HIGH 8.1
CVE-2026-35604

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Fix: 2.63.1+
Fix from $1,950 2026-04-07
Changedetection CRITICAL 9.8
CVE-2026-35490

changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (…

Fix: 0.54.8+
Fix from $2,300 2026-04-07
Ftldns MEDIUM 6.1
CVE-2026-35491

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, Pi-hole FTL suppor…

Fix: 6.6+
Fix from $1,600 2026-04-07
Runzero Platform MEDIUM 5.3
CVE-2026-5380

An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an…

Fix: 4.0.260204.2+
Fix from $1,600 2026-04-07
Runzero Platform MEDIUM 5.8
CVE-2026-5384

An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is…

Fix: 4.0.26021.0+
Fix from $1,600 2026-04-07
Runzero Platform MEDIUM 5.8
CVE-2026-5374

An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. Thi…

Fix: 4.0.260202.0+
Fix from $1,600 2026-04-07
Runzero Platform MEDIUM 6.8
CVE-2026-5378

An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance…

Fix: 4.0.260203.0+
Fix from $1,600 2026-04-07
Pyload HIGH 7.5
CVE-2026-35464

pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin us…

Fix: 2026-04-02+
Fix from $1,950 2026-04-07
Erlang\/inets CRITICAL 9.8
CVE-2026-28808

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when se…

Fix: 9.1.0.6 / 9.3.2.4+
Fix from $2,300 2026-04-07
Directus HIGH 8.1
CVE-2026-35412

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tu…

Fix: 11.16.1+
Fix from $1,950 2026-04-06
Directus HIGH 8.1
CVE-2026-35442

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields w…

Fix: 11.17.0+
Fix from $1,950 2026-04-06
Helm Charts HIGH 8.8
CVE-2026-34972

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1…

Fix: 0.2.62 / 1.14.0+
Fix from $1,950 2026-04-06