Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 5.0
CVE-2026-71201

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.0
CVE-2026-71191

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned UR…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.0
CVE-2026-71192

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.1
CVE-2026-55707

In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-70494

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handl…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-70490

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backen…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.1
CVE-2026-70471

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the co…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.1
CVE-2026-70472

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpo…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.6
CVE-2026-70474

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credenti…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.1
CVE-2026-69262

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized re…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-64630

A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18773

A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gate…

No fix yet
Fix from $1,600 2026-08-04
Milo HIGH 7.5
CVE-2026-62927

In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating author…

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Campaign CRITICAL 9.8
CVE-2026-48333

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exp…

Fix: after 7.4.2
Fix from $2,300 2026-08-03
Unclassified HIGH 8.5
CVE-2026-48113

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL r…

No fix yet
Fix from $1,950 2026-08-03
Nifi CRITICAL 9.1
CVE-2026-68980

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-58139

The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to e…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.7
CVE-2026-62354

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit propo…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-68930

Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were n…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-15254

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing short…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 8.1
CVE-2026-68581

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independen…

No fix yet
Fix from $1,950 2026-08-02
Build Of Keycloak MEDIUM 6.5
CVE-2026-18572

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing…

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 7.5
CVE-2026-16540

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own rec…

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 5.4
CVE-2026-16064

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when qui…

No fix yet
Fix from $1,600 2026-08-02
Unclassified CRITICAL 9.8
CVE-2026-67341

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with …

No fix yet
Fix from $2,300 2026-08-01
Unclassified MEDIUM 5.4
CVE-2026-67310

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of …

No fix yet
Fix from $1,600 2026-08-01
Zephyr MEDIUM 6.5
CVE-2026-2411

Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to …

Fix: 4.5.0+
Fix from $1,600 2026-08-01
Unclassified HIGH 7.4
CVE-2026-18394

Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured v…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 5.4
CVE-2026-54707

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Pri…

No fix yet
Fix from $1,600 2026-07-31
Build Of Keycloak MEDIUM 6.5
CVE-2026-18203

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend p…

No fix yet
Fix from $1,600 2026-07-31