Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.3 CVE-2026-54398 An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or at… Patch available Fix from $1,6002026-06-12 MEDIUM 6.5 CVE-2026-53834 OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to sk… Openclaw 2026.4.27+ Fix from $1,6002026-06-12 HIGH 8.8 CVE-2026-53828 OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner… Openclaw 2026.5.6+ Fix from $1,9502026-06-12 MEDIUM 6.4 CVE-2026-53521 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /s… Mitigation only Fix from $1,6002026-06-12 HIGH 7.1 CVE-2026-47120 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem… Mitigation only Fix from $1,9502026-06-12 MEDIUM 5.3 CVE-2026-49397 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private … Mitigation only Fix from $1,6002026-06-12 HIGH 7.7 CVE-2026-46717 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's d… Mitigation only Fix from $1,9502026-06-12 MEDIUM 6.1 CVE-2026-54397 A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form data… Patch available Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-54362 An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view galaxies that should not have… Patch available Fix from $1,6002026-06-12 MEDIUM 5.1 CVE-2026-54357 An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to si… Patch available Fix from $1,6002026-06-12 HIGH 7.5 CVE-2026-54358 An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same org… Patch available Fix from $1,9502026-06-12 MEDIUM 6.9 CVE-2026-42604 Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full … Mitigation only Fix from $1,6002026-06-12 MEDIUM 6.9 CVE-2026-50008 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-al… Patch available Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-44173 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11… MariaDB 10.6.26 / 10.11.17+ Fix from $1,6002026-06-12 HIGH 7.2 CVE-2026-6739 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patchin… Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-7387 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authoriz… Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-45831 The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a… Chromadb after 1.5.9 Fix from $1,9502026-06-12 HIGH 8.2 CVE-2026-53721 Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule m… Nuxt 3.21.7 / 4.4.7+ Fix from $1,9502026-06-12 HIGH 7.1 CVE-2026-47195 Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level permissions on the invoking me… Mitigation only Fix from $1,9502026-06-12 MEDIUM 6.5 CVE-2026-47238 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subt… Mitigation only Fix from $1,6002026-06-11 HIGH 8.8 CVE-2026-53807 OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip com… Openclaw 2026.5.6+ Fix from $1,9502026-06-11 MEDIUM 6.5 CVE-2026-53808 OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply:… Openclaw 2026.5.6+ Fix from $1,6002026-06-11 HIGH 8.8 CVE-2026-46519 mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes thr… Mitigation only Fix from $1,9502026-06-11 MEDIUM 5.4 CVE-2026-6269 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un… GitLab 18.10.8 / 18.11.5+ Fix from $1,6002026-06-11 MEDIUM 5.5 CVE-2026-49219 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect… Imagemagick 6.9.13-48 / 7.1.2-24+ Fix from $1,6002026-06-10 HIGH 8.1 CVE-2026-53738 Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers wi… Mitigation only Fix from $1,9502026-06-10 HIGH 7.2 CVE-2026-0272 A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Int… Pan Os 10.2.7 / 10.2.10+ Fix from $1,9502026-06-10 HIGH 7.7 CVE-2026-49823 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 HIGH 8.5 CVE-2026-49824 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-48860 Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-ov… Erlang\/otp 11.2.12.9 / 11.6.0.2+ Fix from $1,6002026-06-10