Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.4 CVE-2026-57953 Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write op… Mythic 3.4.0.60+ Fix from $1,6002026-06-29 MEDIUM 5.5 CVE-2026-13508 A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component… Patch available Fix from $1,6002026-06-28 HIGH 8.8 CVE-2026-13484 A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component… Mlflow after 2026-05-26 Fix from $1,9502026-06-28 HIGH 7.6 CVE-2026-58056 RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session… Mitigation only Fix from $1,9502026-06-28 MEDIUM 6.5 CVE-2026-53577 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpoint (GET /api/v1/{tenant… Kestra 1.0.45 / 1.3.21+ Fix from $1,6002026-06-26 HIGH 8.2 CVE-2026-55188 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bu… Mitigation only Fix from $1,9502026-06-26 HIGH 7.7 CVE-2026-55189 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read an… Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.4 CVE-2026-52779 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion… Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-44735 OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares endpoint returns share details … Mitigation only Fix from $1,6002026-06-26 HIGH 7.2 CVE-2026-9640 A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of projec… Lxd 5.0.7 / 5.21.5+ Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-54091 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Patch available Fix from $1,9502026-06-25 HIGH 8.4 CVE-2026-54096 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-54573 Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl to… Mitigation only Fix from $1,6002026-06-25 MEDIUM 6.8 CVE-2026-55411 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lt… Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-11379 GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in whi… GitLab 18.11.6 / 19.0.3+ Fix from $1,6002026-06-25 HIGH 7.1 CVE-2026-52808 Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/… Patch available Fix from $1,9502026-06-24 HIGH 8.8 CVE-2026-56232 Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareK… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.5 CVE-2026-48493 Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_o… Snipe It 8.6.0+ Fix from $1,6002026-06-23 MEDIUM 6.5 CVE-2026-54518 jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.… Jackson Databind 2.21.4 / 3.1.4+ Fix from $1,6002026-06-23 MEDIUM 5.3 CVE-2026-54517 jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.… Jackson Databind 2.21.4 / 3.1.4+ Fix from $1,6002026-06-23 HIGH 7.1 CVE-2026-23513 FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoi… Mitigation only Fix from $1,9502026-06-23 HIGH 7.8 CVE-2026-54555 rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter did not conservatively split … No fix yet Fix from $1,9502026-06-23 HIGH 7.1 CVE-2026-54761 Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway… Traefik 3.6.21 / 3.7.5+ Fix from $1,9502026-06-23 HIGH 7.0 CVE-2026-54321 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox previ… Mitigation only Fix from $1,9502026-06-23 HIGH 8.4 CVE-2026-54320 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitation… Mitigation only Fix from $1,9502026-06-23 MEDIUM 6.5 CVE-2026-54324 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, a cross-tenant authoriz… Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.3 CVE-2026-54021 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, several direct, index-addressed Ol… Open Webui 0.9.6+ Fix from $1,6002026-06-23 MEDIUM 5.3 CVE-2026-54022 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO … Open Webui 0.8.11+ Fix from $1,6002026-06-23 MEDIUM 5.2 CVE-2026-49983 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with --… Deno 2.8.1+ Fix from $1,6002026-06-23 CRITICAL 9.6 CVE-2026-54307 n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflo… N8n 1.123.55 / 2.25.7+ Fix from $2,3002026-06-23