Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
File Access Fix MEDIUM 5.3
CVE-2026-3525

Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated)…

Fix: 8.x-1.2+
Fix from $1,600 2026-03-26
File Access Fix MEDIUM 5.3
CVE-2026-3526

Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated)…

Fix: 8.x-1.2+
Fix from $1,600 2026-03-26
Frigate MEDIUM 6.5
CVE-2026-33469

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an authenticated non-admin user can…

No fix yet
Fix from $1,600 2026-03-26
Everest MEDIUM 5.2
CVE-2026-33015

EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop (StopTransaction), the EVSE c…

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Everest MEDIUM 5.2
CVE-2026-33014

EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorization response restores `author…

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Everest MEDIUM 6.5
CVE-2026-29044

EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the TransactionStarted event, Au…

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Etcd MEDIUM 6.5
CVE-2026-33343

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with R…

Fix: 3.4.42 / 3.5.28+
Fix from $1,600 2026-03-26
Mattermost Server MEDIUM 5.4
CVE-2026-4274

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing memb…

Fix: 10.11.11 / 11.2.3+
Fix from $1,600 2026-03-26
Unclassified MEDIUM 6.9
CVE-2026-4263

Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter  'visi…

Mitigation only
Fix from $1,600 2026-03-26
Unclassified MEDIUM 6.9
CVE-2026-4262

Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'ID' i…

Mitigation only
Fix from $1,600 2026-03-26
Nats Server MEDIUM 6.5
CVE-2026-33217

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs…

Fix: 2.11.15 / 2.12.6+
Fix from $1,600 2026-03-25
N8n MEDIUM 5.3
CVE-2026-33722

n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external s…

Fix: 1.123.23 / 2.6.4+
Fix from $1,600 2026-03-25
Material Icons MEDIUM 5.3
CVE-2026-3210

Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icons: from 0.0.0 before 2.0.4.

Fix: 2.0.4+
Fix from $1,600 2026-03-25
Filerise HIGH 7.1
CVE-2026-33330

FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integrati…

Fix: 3.10.0+
Fix from $1,950 2026-03-24
Parse Server MEDIUM 6.5
CVE-2026-33421

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.53 and 9.6.0-alpha.42, …

Fix: 8.6.53 / 9.6.0+
Fix from $1,600 2026-03-24
Vikunja HIGH 8.1
CVE-2026-33668

Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disable…

Fix: 2.2.1+
Fix from $1,950 2026-03-24
Vikunja MEDIUM 6.5
CVE-2026-33676

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tasks, it populates the `related…

Fix: 2.2.1+
Fix from $1,600 2026-03-24
Vikunja HIGH 8.1
CVE-2026-33316

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled user…

Fix: 2.2.0+
Fix from $1,950 2026-03-24
Nginx Plus MEDIUM 5.4
CVE-2026-28755

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when c…

Fix: 1.28.3 / 1.29.7+
Fix from $1,600 2026-03-24
Vitalsesp HIGH 8.8
CVE-2026-4639

Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform cert…

Fix: after 6.3
Fix from $1,950 2026-03-24
Openclaw MEDIUM 5.3
CVE-2026-27183

OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attacker…

Fix: 2026.3.7+
Fix from $1,600 2026-03-23
Openclaw MEDIUM 6.1
CVE-2026-27646

OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to ini…

Fix: 2026.3.7+
Fix from $1,600 2026-03-23
Avideo HIGH 7.6
CVE-2026-33650

WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" permission can escalate privil…

Fix: after 26.0
Fix from $1,950 2026-03-23
Openclaw HIGH 8.1
CVE-2026-32067

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing pol…

Fix: 2026.2.26+
Fix from $1,950 2026-03-21
Openclaw MEDIUM 5.4
CVE-2026-32895

OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized …

Fix: 2026.2.26+
Fix from $1,600 2026-03-21
Openclaw MEDIUM 6.5
CVE-2026-32058

OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of p…

Fix: 2026.2.26+
Fix from $1,600 2026-03-21
Openclaw HIGH 8.8
CVE-2026-32051

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to in…

Fix: 2026.3.1+
Fix from $1,950 2026-03-21
Openclaw MEDIUM 5.3
CVE-2026-32050

OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized sender…

Fix: 2026.2.25+
Fix from $1,600 2026-03-21
Openclaw HIGH 8.8
CVE-2026-32042

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pa…

Fix: 2026.2.25+
Fix from $1,950 2026-03-21
Discourse MEDIUM 6.5
CVE-2026-33428

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staff user with elevated group me…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-21