Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.7 CVE-2026-48348 Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exp… Animate 23.0.16 / 24.0.14+ Fix from $1,9502026-07-14 MEDIUM 5.9 CVE-2026-47998 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi… Commerce 1.21.0+ Fix from $1,6002026-07-14 HIGH 8.2 CVE-2026-47984 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi… Commerce 1.21.0+ Fix from $1,9502026-07-14 HIGH 8.6 CVE-2026-47988 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi… Commerce 1.21.0+ Fix from $1,9502026-07-14 MEDIUM 6.8 CVE-2026-47996EPSS 20% Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker coul… Commerce 1.21.0+ Fix from $1,6002026-07-14 MEDIUM 5.9 CVE-2026-47997EPSS 9% Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi… Commerce 1.21.0+ Fix from $1,6002026-07-14 HIGH 8.8 CVE-2026-47303 Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. .net 8.0.29 / 9.0.18+ Fix from $1,9502026-07-14 HIGH 8.2 CVE-2026-45075 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGrant… Symfony 7.4.12 / 8.0.12+ Fix from $1,9502026-07-14 HIGH 7.1 CVE-2026-15641 Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user t… Devolutions Server 2026.1.23.0 / 2026.2.12.0+ Fix from $1,9502026-07-14 HIGH 7.3 CVE-2026-9127 A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can all… Mitigation only Fix from $1,9502026-07-14 HIGH 8.3 CVE-2026-62196 OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowl… Openclaw 2026.6.6+ Fix from $1,9502026-07-13 MEDIUM 5.4 CVE-2026-62198 OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to per… Openclaw 2026.6.6+ Fix from $1,6002026-07-13 HIGH 8.8 CVE-2026-62190 OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or pe… Openclaw 2026.6.9+ Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-62191 OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers… Openclaw 2026.6.9+ Fix from $1,9502026-07-13 HIGH 8.1 CVE-2026-62192 OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to … Openclaw 2026.6.9+ Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-62193 OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) … Openclaw 2026.6.9+ Fix from $1,6002026-07-13 HIGH 7.6 CVE-2026-62186 OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust cal… Openclaw 2026.6.8+ Fix from $1,9502026-07-13 HIGH 8.1 CVE-2026-62187 OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configur… Openclaw\/feishu 2026.6.9+ Fix from $1,9502026-07-13 HIGH 8.1 CVE-2026-62188 OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could i… Openclaw\/feishu 2026.6.9+ Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-58408 ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admin/export UI and exfiltrate th… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-62147 The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was e… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-10106 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches th… Mattermost Server 10.11.20 / 11.6.5+ Fix from $1,6002026-07-13 HIGH 7.3 CVE-2026-15541 A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of… Patch available Fix from $1,9502026-07-13 MEDIUM 6.3 CVE-2026-15507 A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the compone… Mitigation only Fix from $1,6002026-07-12 MEDIUM 5.4 CVE-2026-56252 Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scop… Mitigation only Fix from $1,6002026-07-12 HIGH 8.8 CVE-2026-1359 The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … Mitigation only Fix from $1,9502026-07-11 HIGH 8.8 CVE-2026-57215 RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to … Rabbitmq Server 4.2.6+ Fix from $1,9502026-07-10 MEDIUM 6.5 CVE-2026-57217 RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic wr… Rabbitmq Server 4.2.6+ Fix from $1,6002026-07-10 MEDIUM 6.5 CVE-2026-57218 RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth … Rabbitmq Server 4.2.6+ Fix from $1,6002026-07-10 MEDIUM 5.7 CVE-2026-55475 Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid A… Snipe It 8.6.1+ Fix from $1,6002026-07-10