Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified HIGH 7.5
CVE-2026-43977

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout ses…

No fix yet
Fix from $1,950 2026-07-16
Cert Manager HIGH 7.3
CVE-2026-62290

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing an…

Fix: 1.19.6 / 1.20.3+
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.4
CVE-2026-47082

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacat…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-47084

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.8
CVE-2026-63085

Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate…

No fix yet
Fix from $1,950 2026-07-16
N8n Mcp MEDIUM 5.4
CVE-2026-55608

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP…

Fix: 2.57.4+
Fix from $1,600 2026-07-15
Cilium MEDIUM 5.4
CVE-2026-56743

Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-base…

Fix: 1.19.5+
Fix from $1,600 2026-07-15
Unclassified HIGH 8.3
CVE-2026-59258

immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to m…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.9
CVE-2026-61643

FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that po…

Mitigation only
Fix from $1,600 2026-07-15
Better Auth CRITICAL 9.1
CVE-2026-53512

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth toke…

Fix: 1.6.11+
Fix from $2,300 2026-07-15
Better Auth\/sso HIGH 7.1
CVE-2026-53515

Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register…

Fix: 1.6.11+
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.4
CVE-2026-49997

SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::purge_edges in surrealdb…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 8.8
CVE-2026-55242

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.7
CVE-2026-61644

FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint aut…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.1
CVE-2026-54563

Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send pat…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.6
CVE-2026-54560

Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.1
CVE-2026-60087

PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arb…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 7.3
CVE-2026-15752

A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the fil…

Mitigation only
Fix from $1,950 2026-07-14
Twig HIGH 8.2
CVE-2026-49981

Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template insta…

Fix: 3.27.0+
Fix from $1,950 2026-07-14
Twig CRITICAL 9.1
CVE-2026-48807

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replac…

Fix: 3.27.0+
Fix from $2,300 2026-07-14
Twig HIGH 7.5
CVE-2026-48808

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current…

Fix: 3.27.0+
Fix from $1,950 2026-07-14
Twig CRITICAL 9.1
CVE-2026-48806

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP t…

Fix: 3.27.0+
Fix from $2,300 2026-07-14
Twig MEDIUM 6.5
CVE-2026-47732

Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without co…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Unclassified MEDIUM 5.3
CVE-2026-46635

Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic prop…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.5
CVE-2026-59889

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5,…

Mitigation only
Fix from $1,600 2026-07-14
Coldfusion CRITICAL 9.0
CVE-2026-48327

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. …

Mitigation only
Fix from $2,300 2026-07-14
Coldfusion CRITICAL 9.3
CVE-2026-48321

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnera…

Mitigation only
Fix from $2,300 2026-07-14
.net HIGH 8.2
CVE-2026-50528

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

Fix: 8.0.29 / 9.0.18+
Fix from $1,950 2026-07-14
Symfony HIGH 7.5
CVE-2026-48489

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, Defaul…

Fix: 5.4.53 / 6.4.41+
Fix from $1,950 2026-07-14
Animate HIGH 8.1
CVE-2026-48349

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exp…

Fix: 23.0.16 / 24.0.14+
Fix from $1,950 2026-07-14