Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 6.3
CVE-2026-64651

The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.28, the tool relay authorizes …

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-44509

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, previous bug fix…

No fix yet
Fix from $1,600 2026-07-20
Request Tracker CRITICAL 9.1
CVE-2026-44231

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an informa…

Fix: 5.0.10 / 6.0.3+
Fix from $2,300 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63755

SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON D…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63740

SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elemen…

Fix: 3.1.4+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63733

SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with en…

Fix: 3.2.0+
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-16215

A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Ha…

No fix yet
Fix from $1,600 2026-07-19
Unclassified HIGH 7.3
CVE-2026-16200

A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of t…

No fix yet
Fix from $1,950 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-16197

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/…

No fix yet
Fix from $1,600 2026-07-18
Unclassified HIGH 8.2
CVE-2026-10130

QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing account…

No fix yet
Fix from $1,950 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16195

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/w…

No fix yet
Fix from $1,600 2026-07-18
Unclassified HIGH 7.3
CVE-2026-16126

A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm…

No fix yet
Fix from $1,950 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16123

A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the fi…

No fix yet
Fix from $1,600 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16119

A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval…

No fix yet
Fix from $1,600 2026-07-18
Surrealdb HIGH 8.8
CVE-2025-71390

SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access r…

Fix: 2.1.8 / 2.2.6+
Fix from $1,950 2026-07-18
Unclassified HIGH 8.3
CVE-2026-47866

VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Cont…

No fix yet
Fix from $1,950 2026-07-18
Unclassified CRITICAL 9.6
CVE-2026-55518

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_…

No fix yet
Fix from $2,300 2026-07-17
Security Verify Access MEDIUM 6.5
CVE-2026-4938

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.2.0
Fix from $1,600 2026-07-17
Unclassified HIGH 7.1
CVE-2026-14871

osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJ…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-16017

A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the compo…

No fix yet
Fix from $1,600 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62228

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyo…

Fix: 2026.6.5+
Fix from $1,950 2026-07-17
Unclassified HIGH 8.1
CVE-2026-62231

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, …

Mitigation only
Fix from $1,950 2026-07-17
Openclaw MEDIUM 5.4
CVE-2026-62221

OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature i…

Fix: 2026.5.26+
Fix from $1,600 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62223

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execut…

Fix: 2026.5.18+
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.4
CVE-2026-62224

OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attacker…

No fix yet
Fix from $1,600 2026-07-17
Openclaw MEDIUM 5.4
CVE-2026-62225

OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute…

Fix: 2026.5.18+
Fix from $1,600 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62217

OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachab…

Fix: 2026.5.27+
Fix from $1,950 2026-07-17
Openclaw HIGH 7.1
CVE-2026-62219

OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or co…

Fix: 2026.5.26+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.1
CVE-2026-62209

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore …

Fix: 2026.6.5+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62202

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to rega…

Fix: 2026.6.9+
Fix from $1,950 2026-07-17