Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified CRITICAL 9.2
CVE-2026-13738

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to res…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.6
CVE-2025-30238

In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged oper…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72886

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 8.8
CVE-2026-69118

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execut…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 6.9
CVE-2026-21076

Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.9
CVE-2026-21077

Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.5
CVE-2026-18934

The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named …

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-15229

The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated user…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-19350

A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component Ta…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 6.5
CVE-2026-19345

A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manip…

No fix yet
Fix from $4,000 2026-08-09
Unclassified HIGH 7.1
CVE-2026-45808

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A t…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.2
CVE-2026-17594

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user in…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-66059

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. …

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.9
CVE-2026-37171

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, da…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.8
CVE-2026-7867

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option …

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-71433

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the …

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-48076

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.1
CVE-2026-47185

Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authent…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 8.5
CVE-2026-45414

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to th…

No fix yet
Fix from $1,950 2026-08-06
Polaris MEDIUM 6.5
CVE-2026-64640

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permissi…

Fix: after 1.6.0
Fix from $1,600 2026-08-06
Unclassified HIGH 7.3
CVE-2026-19010

A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the c…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19006

A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Gg…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-18997

A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-18992

A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/exec…

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-52466

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming requ…

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.2
CVE-2026-71315

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-f…

No fix yet
Fix from $1,950 2026-08-05
Documentdb Mcp Server MEDIUM 5.5
CVE-2026-18954

Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP clie…

Fix: 1.0.12+
Fix from $1,600 2026-08-05
Answer MEDIUM 6.5
CVE-2026-50749

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary…

Fix: 2.0.2+
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71247

Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71234

Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) a…

No fix yet
Fix from $1,950 2026-08-05