Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Parse Server HIGH 7.2
CVE-2026-29182

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.4 and 9.4.1-alpha.3, Pa…

Fix: 8.6.4+
Fix from $1,950 2026-03-06
Node Server HIGH 7.5
CVE-2026-29087

@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving togeth…

Fix: 1.19.10+
Fix from $1,950 2026-03-06
Zabbix HIGH 8.1
CVE-2026-23925

An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can le…

Fix: 6.0.41 / 7.0.18+
Fix from $1,950 2026-03-06
Cyber Protect MEDIUM 6.5
CVE-2026-28715

Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows)…

Fix: 17.0.41186+
Fix from $1,600 2026-03-06
Openclaw HIGH 8.1
CVE-2026-28473

OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec ap…

Fix: 2026.2.2+
Fix from $1,950 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28474

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist valid…

Fix: 2026.2.6+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.9
CVE-2026-28466

OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke par…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28392

OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any …

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Olivetin HIGH 7.5
CVE-2026-28790

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to term…

Fix: 3000.11.0+
Fix from $1,950 2026-03-05
Hexpm MEDIUM 5.3
CVE-2026-21621

Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privilege Escalation. An API key cr…

Fix: 2026-03-05+
Fix from $1,600 2026-03-05
Build Of Keycloak HIGH 8.1
CVE-2026-3009

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even…

Mitigation only
Fix from $1,950 2026-03-05
Sfx2100 Firmware HIGH 7.8
CVE-2026-29127

The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured w…

No fix yet
Fix from $1,950 2026-03-05
Sfx2100 Firmware HIGH 7.8
CVE-2026-29126

Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver al…

No fix yet
Fix from $1,950 2026-03-05
Vaultwarden HIGH 8.3
CVE-2026-27802

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privile…

Fix: 1.35.4+
Fix from $1,950 2026-03-04
Vaultwarden HIGH 8.3
CVE-2026-27803

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has…

Fix: 1.35.4+
Fix from $1,950 2026-03-04
Device Management Agent HIGH 7.8
CVE-2026-26949

Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local …

Fix: 26.02+
Fix from $1,950 2026-03-04
Checkmk MEDIUM 5.4
CVE-2026-3103

A logic error in the remove_password() function in Checkmk GmbH's Checkmk versions <2.4.0p23, <2.3.0p43, and 2.2.0 (EOL) allows a low-privileged user…

Mitigation only
Fix from $1,600 2026-03-04
Engineering Requirements Management Doors Next MEDIUM 5.4
CVE-2025-13734

IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized acces…

Mitigation only
Fix from $1,600 2026-03-03
Cloud Build CRITICAL 9.8
CVE-2026-3136

An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execut…

Fix: 2026-1-26+
Fix from $2,300 2026-03-03
Clipbucket MEDIUM 6.5
CVE-2026-28354

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws,…

Fix: 5.5.3-59+
Fix from $1,600 2026-02-27
Nest CRITICAL 9.8
CVE-2026-2293

A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization optio…

Mitigation only
Fix from $2,300 2026-02-27
Satellite MEDIUM 6.5
CVE-2025-9572

n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, …

Fix: 3.16.2+
Fix from $1,600 2026-02-27
Securebrowser For Onegate MEDIUM 6.7
CVE-2026-27653

The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary …

Fix: 1.4.8 / 2.0.15+
Fix from $1,600 2026-02-27
Unclassified HIGH 7.1
CVE-2026-25741

Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card updat…

Patch available
Fix from $1,950 2026-02-26
Discourse HIGH 7.5
CVE-2026-26265

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items en…

Fix: 2025.12.0 / 2026.1.1+
Fix from $1,950 2026-02-26
Fleet MEDIUM 6.5
CVE-2026-25963

Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion A…

Fix: 4.80.1+
Fix from $1,600 2026-02-26
Wireguard Portal HIGH 8.8
CVE-2026-27899

WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-ad…

Fix: 2.1.3+
Fix from $1,950 2026-02-26
Openemr MEDIUM 6.5
CVE-2026-24487

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization byp…

Fix: 8.0.0+
Fix from $1,600 2026-02-25
Rustfs CRITICAL 9.1
CVE-2026-27607

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy condi…

Mitigation only
Fix from $2,300 2026-02-25
Openemr MEDIUM 6.5
CVE-2026-25127

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not …

Fix: 8.0.0+
Fix from $1,600 2026-02-25