Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Studiocms MEDIUM 6.3
CVE-2026-32101

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.3.1, the S3 storage manager's isAuthorized() functi…

Fix: 0.3.1+
Fix from $1,600 2026-03-11
Olivetin MEDIUM 6.5
CVE-2026-32102

OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution e…

Fix: after 3000.10.2
Fix from $1,600 2026-03-11
Copyparty MEDIUM 6.5
CVE-2026-32108

Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-option). This vulne…

Fix: 1.20.12+
Fix from $1,600 2026-03-11
Shopware HIGH 7.5
CVE-2026-31887

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows…

Fix: 6.6.10.15 / 6.7.8.1+
Fix from $1,950 2026-03-11
Openproject HIGH 7.1
CVE-2026-30239

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned…

Fix: 17.2.0+
Fix from $1,950 2026-03-11
Neo4j MEDIUM 6.5
CVE-2026-1471

Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the conte…

Fix: 5.26.22 / 2026.01.4+
Fix from $1,600 2026-03-11
Neo4j CRITICAL 9.8
CVE-2026-1524

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c…

Fix: 5.26.22 / 2026.02+
Fix from $2,300 2026-03-11
Argo Workflows HIGH 8.1
CVE-2026-31892

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.1…

Fix: 3.7.11 / 4.0.2+
Fix from $1,950 2026-03-11
Argo Workflows HIGH 7.5
CVE-2026-28229

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow …

Fix: 3.7.11 / 4.0.2+
Fix from $1,950 2026-03-11
Neo4j HIGH 7.2
CVE-2026-1497

Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following …

Fix: 5.26.22 / 2026.02+
Fix from $1,950 2026-03-11
Openclaw HIGH 8.8
CVE-2026-32059

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviati…

Fix: 2026.2.23+
Fix from $1,950 2026-03-11
Commerce HIGH 7.5
CVE-2026-21309

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vuln…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-03-11
Commerce B2b MEDIUM 5.3
CVE-2026-21286

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vuln…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2026-03-11
Commerce B2b HIGH 7.5
CVE-2026-21289

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vuln…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-03-11
Istio MEDIUM 5.3
CVE-2026-31838

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header mat…

Fix: 1.27.8 / 1.28.5+
Fix from $1,600 2026-03-10
Zot HIGH 7.7
CVE-2026-31801

zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0 to 2.1.14, zot’s dist-spec a…

Fix: 2.1.15+
Fix from $1,950 2026-03-10
Parse Server CRITICAL 9.1
CVE-2026-30965

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerab…

Fix: 8.6.21 / 9.5.2+
Fix from $2,300 2026-03-10
Parse Server HIGH 7.5
CVE-2026-30947

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.3 and 8.6.16, class-leve…

Fix: 8.6.16 / 9.5.2+
Fix from $1,950 2026-03-10
Envoy HIGH 8.2
CVE-2026-26308

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filte…

Fix: 1.34.13 / 1.35.8+
Fix from $1,950 2026-03-10
Studiocms HIGH 8.8
CVE-2026-30944

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoi…

Fix: 0.4.0+
Fix from $1,950 2026-03-10
Studiocms HIGH 7.1
CVE-2026-30945

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens…

Fix: 0.4.0+
Fix from $1,950 2026-03-10
Azure Automation Hybrid Worker Windows Extension HIGH 7.8
CVE-2026-26141

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

Fix: 1.3.74+
Fix from $1,950 2026-03-10
Pocket Id HIGH 7.1
CVE-2026-28513

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects…

Fix: 2.4.0+
Fix from $1,950 2026-03-10
Parse Server CRITICAL 9.8
CVE-2026-30863

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, …

Fix: 8.6.10 / 9.5.0+
Fix from $2,300 2026-03-07
Parse Server MEDIUM 5.3
CVE-2026-30854

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3.1-alpha.3 to before version …

Fix: 9.5.0+
Fix from $1,600 2026-03-07
Netmaker MEDIUM 6.5
CVE-2026-29195

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lacks validation to prevent an ad…

Fix: 1.5.0+
Fix from $1,600 2026-03-07
Netmaker HIGH 8.1
CVE-2026-29194

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validates host JWT tokens. When a ro…

Fix: 1.5.0+
Fix from $1,950 2026-03-07
Flowise HIGH 8.8
CVE-2026-30820

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that…

Fix: 3.0.13+
Fix from $1,950 2026-03-07
Mercurius HIGH 8.2
CVE-2026-30241

Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDepth limit on GraphQL subscripti…

Fix: 16.8.0+
Fix from $1,950 2026-03-06
Parse Server HIGH 7.2
CVE-2026-30229

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.6 and 9.5.0-alpha.4, th…

Fix: 8.6.6+
Fix from $1,950 2026-03-06