Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Superset MEDIUM 6.5
CVE-2026-23984

An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only ver…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Superset MEDIUM 6.5
CVE-2026-23982

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a d…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Kargo CRITICAL 9.9
CVE-2026-27112

Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the batch resource creation endpoi…

Fix: 1.7.8 / 1.8.11+
Fix from $2,300 2026-02-20
Unclassified MEDIUM 6.3
CVE-2026-2819

A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/i…

Mitigation only
Fix from $1,600 2026-02-20
Cilium MEDIUM 5.4
CVE-2026-26963

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit tra…

Fix: 1.18.6+
Fix from $1,600 2026-02-20
Openclaw MEDIUM 6.5
CVE-2026-26328

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authorization could be satisfied by se…

Fix: 2026.2.14+
Fix from $1,600 2026-02-20
Openclaw HIGH 7.5
CVE-2026-26316

OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authentica…

Fix: 2026.2.13+
Fix from $1,950 2026-02-19
Unclassified HIGH 7.1
CVE-2026-26205

opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path`…

Patch available
Fix from $1,950 2026-02-19
Alfresco Content Services HIGH 7.5
CVE-2026-26336

Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" en…

Fix: 25.3+
Fix from $1,950 2026-02-19
Gogs HIGH 8.8
CVE-2026-25232

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository col…

Fix: 0.14.1+
Fix from $1,950 2026-02-19
Unclassified HIGH 7.8
CVE-2025-4960

The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to m…

Mitigation only
Fix from $1,950 2026-02-19
Enterprise Server MEDIUM 6.5
CVE-2026-1999

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge their own pull request into a r…

Fix: 3.17.11 / 3.18.5+
Fix from $1,600 2026-02-18
Unclassified MEDIUM 5.3
CVE-2026-2126

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versi…

Mitigation only
Fix from $1,600 2026-02-18
Lavinmq HIGH 8.1
CVE-2026-25767

LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels…

Fix: 2.6.8+
Fix from $1,950 2026-02-12
Grafana MEDIUM 5.3
CVE-2026-21722

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one c…

Fix: 11.6.10 / 12.1.6+
Fix from $1,600 2026-02-12
macOS MEDIUM 5.5
CVE-2026-20624

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app…

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-02-11
Learning MEDIUM 5.3
CVE-2026-26031

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified…

Fix: 2.44.0+
Fix from $1,600 2026-02-11
Vaultwarden MEDIUM 6.5
CVE-2026-26012

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization mem…

Fix: 1.35.3+
Fix from $1,600 2026-02-11
Kanboard HIGH 8.4
CVE-2026-25924

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an…

Fix: 1.2.50+
Fix from $1,950 2026-02-11
Placipy CRITICAL 9.8
CVE-2026-25875

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorization middleware trusts client-co…

Mitigation only
Fix from $2,300 2026-02-09
Filebrowser HIGH 8.1
CVE-2026-25890

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Pr…

Fix: 2.57.1+
Fix from $1,950 2026-02-09
Placipy CRITICAL 9.1
CVE-2026-25811

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier direc…

Mitigation only
Fix from $2,300 2026-02-09
Wukong Crm HIGH 8.8
CVE-2026-2141

A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/ka…

Fix: after 11.3.3
Fix from $1,950 2026-02-08
Wekan MEDIUM 6.5
CVE-2026-2208

A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the compo…

Fix: 8.21+
Fix from $1,600 2026-02-08
Wekan MEDIUM 6.5
CVE-2026-25565

WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than r…

Fix: 8.19+
Fix from $1,600 2026-02-07
Wekan MEDIUM 5.4
CVE-2026-25566

WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without …

Fix: 8.19+
Fix from $1,600 2026-02-07
Wekan HIGH 8.8
CVE-2026-25859

Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resu…

Fix: 8.20+
Fix from $1,950 2026-02-07
Wekan HIGH 7.5
CVE-2026-25561

WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifier…

Fix: 8.19+
Fix from $1,950 2026-02-07
Deepaudit MEDIUM 6.5
CVE-2026-25729

DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access control vulnerability in the /a…

Fix: after 3.0.4
Fix from $1,600 2026-02-06
Opencloud Reva HIGH 8.1
CVE-2026-23989

REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud all…

Fix: 2.40.3 / 2.42.3+
Fix from $1,950 2026-02-06