Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.4 CVE-2026-19670 Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /au… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-55163 Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(ro… Fix unknown Fix from $4,0002026-08-18 HIGH 8.8 CVE-2026-48508 Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_p… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-61574 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpo… Fix unknown Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-74906 SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the vi… Fix unknown Fix from $4,9002026-08-18 HIGH 8.3 CVE-2026-9816 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and arc… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-9859 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the … Fix unknown Fix from $4,0002026-08-17 CRITICAL 9.6 CVE-2026-71424 Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} end… Fix unknown Fix from $5,7502026-08-17 MEDIUM 5.3 CVE-2026-11817 This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-o… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.5 CVE-2026-75480 OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users … Fix unknown Fix from $4,0002026-08-17 HIGH 7.5 CVE-2026-71518 Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to acces… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.2 CVE-2026-44846 JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user with the users.invite_user… Fix unknown Fix from $4,0002026-08-17 CRITICAL 9.9 CVE-2026-66792 A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileg… Fix unknown Fix from $5,7502026-08-17 MEDIUM 6.3 CVE-2026-16048 Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles w… Mattermost Server Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.3 CVE-2026-10527 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which all… Mattermost Server Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.4 CVE-2026-16044 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive impo… Mattermost Server Fix unknown Fix from $4,0002026-08-17 HIGH 7.0 CVE-2026-18674 On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlP… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-73059 stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requ… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.5 CVE-2026-19726 The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contribu… Fix unknown Fix from $4,0002026-08-16 CRITICAL 9.8 CVE-2026-19598 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to,… No fix yet Fix from $5,7502026-08-15 HIGH 8.1 CVE-2026-19629 A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission o… No fix yet Fix from $4,9002026-08-14 HIGH 7.1 CVE-2026-49989 CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they … No fix yet Fix from $4,9002026-08-14 HIGH 7.7 CVE-2026-72859 Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 … No fix yet Fix from $4,9002026-08-14 MEDIUM 5.8 CVE-2026-73049 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden a… No fix yet Fix from $4,0002026-08-14 HIGH 8.8 CVE-2026-72831 The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiCo… No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-73841 OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go an… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-73305 Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking app… No fix yet Fix from $4,9002026-08-13 HIGH 7.7 CVE-2026-72672 The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data … No fix yet Fix from $4,9002026-08-13 MEDIUM 5.4 CVE-2026-72673 Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properl… No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-72643 Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to… No fix yet Fix from $4,9002026-08-13