Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.3 CVE-2026-55479 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkou… Patch available Fix from $1,6002026-07-10 HIGH 7.1 CVE-2026-55460 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.d… Snipe It 8.6.2+ Fix from $1,9502026-07-10 HIGH 7.4 CVE-2026-55672 ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device … Patch available Fix from $1,9502026-07-10 HIGH 8.6 CVE-2026-55638 9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /co… Patch available Fix from $1,9502026-07-10 HIGH 7.1 CVE-2026-39903 Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/A… Patch available Fix from $1,9502026-07-10 HIGH 8.1 CVE-2026-22659 FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated moderators to perform unauth… Patch available Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-40452 Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value dat… Mitigation only Fix from $1,9502026-07-10 MEDIUM 6.3 CVE-2026-15332 A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of t… Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-5069 The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, … Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-15320 A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pi… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.3 CVE-2026-15318 A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqt… Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-59227 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required on… Open Webui 0.10.0+ Fix from $1,6002026-07-09 MEDIUM 5.4 CVE-2026-59212 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_knowledge_file_access only ch… Open Webui Patch available Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-61474 An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to add attributes to submit a sha… Patch available Fix from $1,6002026-07-09 HIGH 8.8 CVE-2026-15125 Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox v… Chrome 150.0.7871.115+ Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-58494 Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory p… Patch available Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-58211 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be regi… Nats Server 2.12.12 / 2.14.3+ Fix from $1,6002026-07-08 HIGH 7.1 CVE-2026-35210 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vul… Opencti 7.260326.0+ Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-35211 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exp… Opencti 7.260401.0+ Fix from $1,6002026-07-08 HIGH 8.8 CVE-2026-8800 Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 202… Moveit Transfer 2025.0.7 / 2025.1.3+ Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-58254 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destinati… Nats Server 2.12.8 / 2.14.3+ Fix from $1,6002026-07-08 HIGH 8.1 CVE-2026-54652 Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the… Patch available Fix from $1,9502026-07-08 MEDIUM 5.3 CVE-2026-60125 MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not enforce the per-organisation mo… Patch available Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-56775 n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-… N8n 1.123.55 / 2.25.7+ Fix from $1,6002026-07-08 HIGH 7.4 CVE-2026-56776 n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint, which authorizes… N8n 1.123.55 / 2.25.7+ Fix from $1,9502026-07-08 MEDIUM 6.4 CVE-2026-56778 n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, which authorizes access using… N8n 2.25.7 / 2.26.2+ Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-56220 Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows read-only org members to insert… Mitigation only Fix from $1,6002026-07-08 HIGH 8.8 CVE-2026-56086 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug… Data Domain Operating System 7.13.1.80 / 8.3.1.40+ Fix from $1,9502026-07-08 HIGH 8.2 CVE-2026-55428 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tail… Coder 2.29.17 / 2.32.7+ Fix from $1,9502026-07-08 MEDIUM 5.9 CVE-2026-54698 Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table compu… Graphql Engine after 2.49.2 Fix from $1,6002026-07-07