Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.9 CVE-2026-42604 Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full … Mitigation only Fix from $1,6002026-06-12 MEDIUM 6.9 CVE-2026-50008 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-al… Patch available Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-44173 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11… MariaDB 10.6.26 / 10.11.17+ Fix from $1,6002026-06-12 HIGH 7.2 CVE-2026-6739 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patchin… Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-7387 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authoriz… Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-45831 The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a… Chromadb after 1.5.9 Fix from $1,9502026-06-12 HIGH 8.2 CVE-2026-53721 Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule m… Nuxt 3.21.7 / 4.4.7+ Fix from $1,9502026-06-12 HIGH 7.1 CVE-2026-47195 Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level permissions on the invoking me… Mitigation only Fix from $1,9502026-06-12 MEDIUM 6.5 CVE-2026-47238 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subt… Mitigation only Fix from $1,6002026-06-11 HIGH 8.8 CVE-2026-53807 OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip com… Openclaw 2026.5.6+ Fix from $1,9502026-06-11 MEDIUM 6.5 CVE-2026-53808 OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply:… Openclaw 2026.5.6+ Fix from $1,6002026-06-11 HIGH 8.8 CVE-2026-46519 mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes thr… Mitigation only Fix from $1,9502026-06-11 MEDIUM 5.4 CVE-2026-6269 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un… GitLab 18.10.8 / 18.11.5+ Fix from $1,6002026-06-11 MEDIUM 5.5 CVE-2026-49219 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect… Imagemagick 6.9.13-48 / 7.1.2-24+ Fix from $1,6002026-06-10 HIGH 8.1 CVE-2026-53738 Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers wi… Mitigation only Fix from $1,9502026-06-10 HIGH 7.2 CVE-2026-0272 A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Int… Pan Os 10.2.7 / 10.2.10+ Fix from $1,9502026-06-10 HIGH 7.7 CVE-2026-49823 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 HIGH 8.5 CVE-2026-49824 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-48860 Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-ov… Erlang\/otp 11.2.12.9 / 11.6.0.2+ Fix from $1,6002026-06-10 CRITICAL 9.1 CVE-2026-45550 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smo… Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-45552 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares … Mitigation only Fix from $2,3002026-06-10 HIGH 8.5 CVE-2026-45549 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/a… Mitigation only Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-24724 An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit… File Station 5.5.6.5243+ Fix from $1,9502026-06-10 CRITICAL 10.0 CVE-2026-48303 Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbi… Campaign 7.4.3+ Fix from $2,3002026-06-09 HIGH 8.4 CVE-2026-47929 ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code executio… Coldfusion Mitigation only Fix from $1,9502026-06-09 MEDIUM 6.3 CVE-2026-47910 Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read.… Dreamweaver 21.8+ Fix from $1,6002026-06-09 HIGH 7.8 CVE-2026-45490 Improper authorization in .NET allows an authorized attacker to elevate privileges locally. .net 8.0.28 / 9.0.17+ Fix from $1,9502026-06-09 MEDIUM 5.3 CVE-2026-41852 A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 HIGH 7.1 CVE-2026-48507 Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `user… Snipe It 8.6.0+ Fix from $1,9502026-06-08 MEDIUM 5.3 CVE-2026-7765 Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creat… Checkmk Mitigation only Fix from $1,6002026-06-08