Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 6.3
CVE-2026-62323

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI acc…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.1
CVE-2026-55502

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even …

No fix yet
Fix from $1,950 2026-07-31
Mcp Toolbox For Databases HIGH 7.7
CVE-2026-14538

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1…

Fix: after 1.4.0
Fix from $1,950 2026-07-31
Mcp Toolbox For Databases CRITICAL 9.8
CVE-2026-14537

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated at…

No fix yet
Fix from $2,300 2026-07-31
Unclassified MEDIUM 6.6
CVE-2026-65835

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResour…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.8
CVE-2026-67347

Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-location.service.ts and asset.se…

No fix yet
Fix from $1,600 2026-07-30
Calico MEDIUM 6.5
CVE-2026-41187

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy,…

Fix: 3.21.7 / 3.22.4+
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-14923

The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and u…

No fix yet
Fix from $1,600 2026-07-30
Campaign CRITICAL 9.8
CVE-2026-48449

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …

Fix: after 7.4.2
Fix from $2,300 2026-07-30
Pydantic Ai MEDIUM 6.5
CVE-2026-65975

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.…

Fix: 1.107.1 / 2.5.0+
Fix from $1,600 2026-07-29
GitLab MEDIUM 5.3
CVE-2026-6336

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under …

Fix: 19.0.5 / 19.1.3+
Fix from $1,600 2026-07-29
Unclassified CRITICAL 9.3
CVE-2026-18236

A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or in…

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 8.2
CVE-2026-54693

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email …

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.2
CVE-2026-18255

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a membe…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.5
CVE-2026-44944

An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects…

No fix yet
Fix from $1,950 2026-07-29
Traffic Server HIGH 8.2
CVE-2026-58159

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-10656

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions u…

No fix yet
Fix from $2,300 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-66064

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened f…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-54719

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?…

No fix yet
Fix from $1,950 2026-07-28
Bridge HIGH 8.2
CVE-2026-48390

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerabili…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Bridge HIGH 8.6
CVE-2026-48396

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An a…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.5
CVE-2026-7868

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrat…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 8.8
CVE-2026-14167

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management du…

No fix yet
Fix from $1,950 2026-07-28
macOS HIGH 7.1
CVE-2026-43672

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26…

Fix: 14.8.8 / 15.7.8+
Fix from $1,950 2026-07-27
Artifactory HIGH 8.8
CVE-2026-42016

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signa…

Fix: 7.133.11+
Fix from $1,950 2026-07-27
Devolutions Server HIGH 8.8
CVE-2026-17568

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the …

Fix: 2026.1.24.0 / 2026.2.14.0+
Fix from $1,950 2026-07-27
Unclassified MEDIUM 6.3
CVE-2026-17529

A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The …

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.3
CVE-2026-17530

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the…

No fix yet
Fix from $1,600 2026-07-27
Connection Manager For Objectscale HIGH 8.0
CVE-2026-59689

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF all…

Fix: 7.2.54.19 / 7.2.63.3+
Fix from $1,950 2026-07-27
Unclassified HIGH 8.1
CVE-2026-8789

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce ver…

No fix yet
Fix from $1,950 2026-07-24