Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Discourse MEDIUM 5.4
CVE-2026-33251

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass vulnerability i…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-20
Discourse MEDIUM 5.4
CVE-2026-33291

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators can create Zendesk tickets f…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-20
Vikunja MEDIUM 5.4
CVE-2026-33312

Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, the `DELETE /api/v1/projects/:…

Fix: 2.2.0+
Fix from $1,600 2026-03-20
Zitadel MEDIUM 5.3
CVE-2026-33132

ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users to bypass organization enforce…

Fix: 3.4.9 / 4.12.3+
Fix from $1,600 2026-03-20
Discourse HIGH 8.2
CVE-2026-31805

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plu…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,950 2026-03-20
Heimdall HIGH 7.5
CVE-2026-32811

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC decision API mode with version…

Fix: 0.17.11+
Fix from $1,950 2026-03-20
Siyuan CRITICAL 9.8
CVE-2026-32767

SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextS…

Fix: 3.6.1+
Fix from $2,300 2026-03-20
Filebrowser MEDIUM 6.5
CVE-2026-32758

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6…

Fix: 2.62.0+
Fix from $1,600 2026-03-20
Filebrowser MEDIUM 6.5
CVE-2026-32761

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6…

Fix: 2.62.0+
Fix from $1,600 2026-03-20
Discourse MEDIUM 5.4
CVE-2026-33410

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two authorization issues in the cha…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-19
Openclaw HIGH 7.1
CVE-2026-32035

OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag t…

Fix: 2026.3.2+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32027

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly eligible for gro…

Fix: 2026.2.26+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 5.3
CVE-2026-32028

OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-message reaction notifications, al…

Fix: 2026.2.25+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32021

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist implementation that accepts muta…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw HIGH 7.1
CVE-2026-32023

OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch w…

Fix: 2026.2.24+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 5.4
CVE-2026-32001

OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated with a shared gateway token to …

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw HIGH 8.1
CVE-2026-32005

OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block_action, view_submission, a…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Discourse MEDIUM 5.3
CVE-2026-27936

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted …

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-19
Discourse MEDIUM 6.5
CVE-2026-28282

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-po…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-19
Openemr HIGH 8.1
CVE-2026-33302

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `A…

Fix: 8.0.0.2+
Fix from $1,950 2026-03-19
Openclaw HIGH 8.6
CVE-2026-31998

OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to all…

Fix: 2026.2.24+
Fix from $1,950 2026-03-19
Juju HIGH 8.8
CVE-2026-32693

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update th…

Fix: 3.6.19+
Fix from $1,950 2026-03-18
Openclaw MEDIUM 6.5
CVE-2026-22170

OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom config…

Fix: 2026.2.22+
Fix from $1,600 2026-03-18
Craft Cms CRITICAL 9.8
CVE-2026-32267EPSS 8%

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, …

Fix: 4.17.6 / 5.9.12+
Fix from $2,300 2026-03-16
Fastmcp MEDIUM 6.5
CVE-2025-69196

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter…

Fix: 2.14.2+
Fix from $1,600 2026-03-16
Mattermost Server MEDIUM 6.6
CVE-2026-2462

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default ad…

Fix: 10.11.11 / 11.2.3+
Fix from $1,600 2026-03-16
Pyjwt HIGH 7.5
CVE-2026-32597

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515…

Fix: 2.12.0+
Fix from $1,950 2026-03-13
Tinyauth MEDIUM 6.5
CVE-2026-32245

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authori…

Fix: after 5.0.2
Fix from $1,600 2026-03-12
Unclassified MEDIUM 6.3
CVE-2026-3977

A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. T…

Patch available
Fix from $1,600 2026-03-12
Openemr MEDIUM 6.5
CVE-2026-32123

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for gro…

Fix: 8.0.0.1+
Fix from $1,600 2026-03-11