Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Litellm HIGH 8.8
CVE-2026-35029EPSS 26%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce a…

Fix: 1.83.0+
Fix from $1,950 2026-04-06
Hi Led Wr120 G2 Firmware CRITICAL 9.1
CVE-2026-5574

A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBr…

No fix yet
Fix from $2,300 2026-04-05
Praisonai CRITICAL 9.1
CVE-2026-34953

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal …

Fix: 4.5.97+
Fix from $2,300 2026-04-03
Cups MEDIUM 6.3
CVE-2026-27447

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd…

Fix: after 2.4.16
Fix from $1,600 2026-04-03
Juju MEDIUM 6.5
CVE-2025-68153

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special ope…

Fix: after 3.6.18
Fix from $1,600 2026-04-03
Azure Kubernetes Service CRITICAL 9.8
CVE-2026-33105

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Sre Agent HIGH 7.5
CVE-2026-32173

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-04-03
Azure Ai Foundry CRITICAL 9.8
CVE-2026-32213

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Pdfding HIGH 7.5
CVE-2026-34376

PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.0, an access-con…

Fix: 1.7.0+
Fix from $1,950 2026-04-01
Xenforo HIGH 8.8
CVE-2025-71278

XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version …

Fix: 2.3.5+
Fix from $1,950 2026-04-01
Siyuan HIGH 7.5
CVE-2026-34453

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected docum…

Fix: 3.6.2+
Fix from $1,950 2026-03-31
Pdfding MEDIUM 6.5
CVE-2026-34586

PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.1, check_shared_…

Fix: 1.7.1+
Fix from $1,600 2026-03-31
Scitokens Cpp Library HIGH 8.1
CVE-2026-32726

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authoriz…

Fix: 1.4.1+
Fix from $1,950 2026-03-31
Parse Server CRITICAL 9.1
CVE-2026-34532

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, …

Fix: 8.6.67 / 9.7.0+
Fix from $2,300 2026-03-31
Openclaw MEDIUM 6.5
CVE-2026-33576

OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can forc…

Fix: 2026.3.28+
Fix from $1,600 2026-03-31
Openclaw HIGH 8.1
CVE-2026-33577

OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operato…

Fix: 2026.3.28+
Fix from $1,950 2026-03-31
Openclaw CRITICAL 9.9
CVE-2026-33579

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into th…

Fix: 2026.3.28+
Fix from $2,300 2026-03-31
Dnsdist MEDIUM 6.5
CVE-2026-24029

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the AC…

Fix: 1.9.12 / 2.0.3+
Fix from $1,600 2026-03-31
Lollms HIGH 8.3
CVE-2026-0562

A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging…

Fix: after 2.1.0
Fix from $1,950 2026-03-29
Openclaw HIGH 7.1
CVE-2026-32972

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to acce…

Fix: 2026.3.11+
Fix from $1,950 2026-03-29
Openclaw HIGH 7.5
CVE-2026-32978

OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain scri…

Fix: 2026.3.11+
Fix from $1,950 2026-03-29
Openclaw HIGH 8.4
CVE-2026-32918

OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent…

Fix: 2026.3.11+
Fix from $1,950 2026-03-29
Openclaw MEDIUM 6.1
CVE-2026-32919

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attac…

Fix: 2026.3.11+
Fix from $1,600 2026-03-29
Openclaw MEDIUM 5.4
CVE-2026-32923

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails to enforce member users and r…

Fix: 2026.3.11+
Fix from $1,600 2026-03-29
Openclaw CRITICAL 9.8
CVE-2026-32924

OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p…

Fix: 2026.3.12+
Fix from $2,300 2026-03-29
Openclaw HIGH 8.8
CVE-2026-32914

OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-author…

Fix: 2026.3.12+
Fix from $1,950 2026-03-29
Openclaw HIGH 8.8
CVE-2026-32915

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolv…

Fix: 2026.3.11+
Fix from $1,950 2026-03-29
Avideo MEDIUM 5.3
CVE-2026-34364

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category lis…

Fix: after 26.0
Fix from $1,600 2026-03-27
Unpublished Node Permissions HIGH 7.5
CVE-2026-4933

Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions…

Fix: 8.x-1.7+
Fix from $1,950 2026-03-26
Artificial Intelligence HIGH 7.5
CVE-2026-3573

Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affects AI (Artificial Intelligence…

Fix: 1.1.11 / 1.2.12+
Fix from $1,950 2026-03-26