Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.4 CVE-2026-56694 NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fai… Patch available Fix from $1,6002026-06-23 CRITICAL 10.0 CVE-2026-27604 FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas… Mitigation only Fix from $2,3002026-06-23 HIGH 7.7 CVE-2026-56268 Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parame… Flowise 3.1.2+ Fix from $1,9502026-06-22 HIGH 8.7 CVE-2026-54281 Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass vulnerability exists in @nestj… Mitigation only Fix from $1,9502026-06-22 HIGH 7.1 CVE-2026-41048 Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like … Qsnapper 1.3.3+ Fix from $1,9502026-06-22 HIGH 7.1 CVE-2026-41049 Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus… Qsnapper 1.3.3+ Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-56424 MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/edita… Misp 2.5.42+ Fix from $1,9502026-06-22 MEDIUM 6.3 CVE-2026-44911 Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submi… Nifi 2.10.0+ Fix from $1,6002026-06-22 MEDIUM 6.3 CVE-2026-12797 A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_h… Litellm after 1.82.5 Fix from $1,6002026-06-21 HIGH 7.5 CVE-2026-50559 Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.… Quarkus 3.20.6.2 / 3.27.4.1+ Fix from $1,9502026-06-19 CRITICAL 10.0 CVE-2026-48772 ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY U… Proxysql 3.0.9+ Fix from $2,3002026-06-19 HIGH 7.1 CVE-2026-48089 DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instance with one or more public ass… Patch available Fix from $1,9502026-06-19 HIGH 8.1 CVE-2026-47339 Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authentica… Apisix 3.17.0+ Fix from $1,9502026-06-19 MEDIUM 5.5 CVE-2026-56074 PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to … Mitigation only Fix from $1,6002026-06-18 HIGH 8.8 CVE-2026-56075 PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding … Mitigation only Fix from $1,9502026-06-18 MEDIUM 5.9 CVE-2026-10741 Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated… Mitigation only Fix from $1,6002026-06-17 CRITICAL 9.8 CVE-2026-54803 Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-48781 Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob int… Patch available Fix from $2,3002026-06-17 MEDIUM 6.5 CVE-2026-42357 Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to acces… Dolphinscheduler 3.4.2+ Fix from $1,6002026-06-17 CRITICAL 9.8 CVE-2026-32966 DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache … Dolphinscheduler 3.4.2+ Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-32967 Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before… Dolphinscheduler 3.4.2+ Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-48776 LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versio… Langgraph Sdk 0.3.15+ Fix from $2,3002026-06-17 MEDIUM 5.4 CVE-2026-53860 OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through con… Openclaw 2026.5.7+ Fix from $1,6002026-06-16 HIGH 8.3 CVE-2026-53853 OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments … Openclaw 2026.5.12+ Fix from $1,9502026-06-16 MEDIUM 6.5 CVE-2026-53854 OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit… Openclaw 2026.4.25+ Fix from $1,6002026-06-16 HIGH 8.1 CVE-2026-53855 OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell po… Openclaw 2026.4.2+ Fix from $1,9502026-06-16 MEDIUM 6.5 CVE-2026-5149 The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submissio… Mitigation only Fix from $1,6002026-06-16 HIGH 7.5 CVE-2026-47777 Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts … Patch available Fix from $1,9502026-06-15 HIGH 8.8 CVE-2016-20075 WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, au… No fix yet Fix from $1,9502026-06-15 HIGH 7.1 CVE-2026-34023 The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability in the WebSocket communicati… Mitigation only Fix from $1,9502026-06-15