Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.9 CVE-2026-53935 Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the abil… Patch available Fix from $1,6002026-07-07 HIGH 8.7 CVE-2026-50529 DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns … Patch available Fix from $1,9502026-07-07 MEDIUM 5.4 CVE-2026-55435 Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.… Coder 2.32.7 / 2.33.8+ Fix from $1,6002026-07-07 MEDIUM 5.9 CVE-2026-12352 This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device. Mitigation only Fix from $1,6002026-07-07 CRITICAL 9.9 CVE-2026-34047 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket boots… Patch available Fix from $2,3002026-07-07 MEDIUM 5.3 CVE-2026-53642 FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Require Email Confirmation" setti… Mitigation only Fix from $1,6002026-07-06 MEDIUM 6.5 CVE-2026-32718 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation … Patch available Fix from $1,6002026-07-06 HIGH 8.5 CVE-2026-54765 Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve tw… Traefik 3.7.6+ Fix from $1,9502026-07-06 HIGH 7.7 CVE-2026-42331 FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an … Mitigation only Fix from $1,9502026-07-06 HIGH 8.8 CVE-2026-14536 Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credential… Devolutions Server after 2026.2.9.0 Fix from $1,9502026-07-06 MEDIUM 6.3 CVE-2026-14716 A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. Impacted is the function MethodRouter.Handle of the file i… Mitigation only Fix from $1,6002026-07-05 HIGH 8.9 CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass Patch available Fix from $1,9502026-07-03 HIGH 8.1 CVE-2026-28744 Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks. Patch available Fix from $1,9502026-07-03 HIGH 8.8 CVE-2026-27775 Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-… Patch available Fix from $1,9502026-07-03 CRITICAL 9.8 CVE-2026-27780 Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass b… Patch available Fix from $2,3002026-07-03 HIGH 8.1 CVE-2026-28699 Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication. Patch available Fix from $1,9502026-07-03 HIGH 7.1 CVE-2026-28740 Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lac… Patch available Fix from $1,9502026-07-03 HIGH 8.5 CVE-2026-26231 Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user c… Patch available Fix from $1,9502026-07-03 HIGH 8.8 CVE-2026-54998 Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Exchange Online No fix yet Fix from $1,9502026-07-02 HIGH 7.3 CVE-2026-8079 In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request dur… Flowmon 12.5.9 / 13.0.11+ Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-56842 A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Netwo… Unifi Network Application 10.4.57+ Fix from $1,9502026-07-02 MEDIUM 5.0 CVE-2026-14340 An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App instal… Enterprise Server 3.16.20 / 3.17.17+ Fix from $1,6002026-07-01 CRITICAL 9.6 CVE-2026-53492 containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Devic… Containerd 2.1.9 / 2.2.5+ Fix from $2,3002026-07-01 MEDIUM 5.3 CVE-2026-56152 Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrai… Endpoint Security 8.19.13 / 9.2.7+ Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-53902 MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated u… Mycomplianceoffice Mitigation only Fix from $1,6002026-07-01 HIGH 7.1 CVE-2026-53905 MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authe… Mycomplianceoffice Mitigation only Fix from $1,9502026-07-01 CRITICAL 9.8 CVE-2026-7663 IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t… Langflow 1.10.0+ Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48286 Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbi… Campaign after 7.4.3 Fix from $2,3002026-06-30 HIGH 8.1 CVE-2026-57950 ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers… Patch available Fix from $1,9502026-06-29 MEDIUM 6.5 CVE-2026-57951 Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypasse… Mythic 3.4.0.60+ Fix from $1,6002026-06-29