Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.5 CVE-2026-21036 Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information. Internet 30.0.0.39+ Fix from $1,6002026-06-05 HIGH 7.8 CVE-2026-21031 Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required f… Android Mitigation only Fix from $1,9502026-06-05 MEDIUM 5.4 CVE-2026-42547 IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users… Mitigation only Fix from $1,6002026-06-04 HIGH 8.6 CVE-2026-41235 Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell li… Mitigation only Fix from $1,9502026-06-04 MEDIUM 6.3 CVE-2026-10815 A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown … Mitigation only Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-10860 A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to … Misp 2.5.39+ Fix from $1,6002026-06-04 CRITICAL 9.9 CVE-2026-41283 OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which… Mitigation only Fix from $2,3002026-06-04 HIGH 7.4 CVE-2025-14774 Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. T Mac Plus Mitigation only Fix from $1,9502026-06-03 HIGH 8.1 CVE-2026-44654 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete f… Librechat 0.8.5+ Fix from $1,9502026-06-02 CRITICAL 9.1 CVE-2026-35482 alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox esca… Alf 2.0-M5-2606+ Fix from $2,3002026-06-02 HIGH 7.5 CVE-2026-3514 In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health … Prefect 3.6.22+ Fix from $1,9502026-06-02 HIGH 7.8 CVE-2025-32348 In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privi… Android Mitigation only Fix from $1,9502026-06-01 CRITICAL 9.1 CVE-2026-22872 Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantR… Capsule 0.13.0+ Fix from $2,3002026-06-01 MEDIUM 6.3 CVE-2026-10211 A vulnerability was determined in AstrBotDevs AstrBot 4.23.6. Affected by this issue is the function _normalize_rw_path of the file astrbot/core/tool… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-49376 In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin Teamcity 2026.1+ Fix from $1,6002026-05-29 CRITICAL 9.1 CVE-2026-48501 GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF … Cli 2.93.0+ Fix from $2,3002026-05-29 MEDIUM 6.5 CVE-2026-35673 OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked t… Openclaw 2026.4.29+ Fix from $1,6002026-05-29 HIGH 8.8 CVE-2026-35674 OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged comma… Openclaw 2026.5.18+ Fix from $1,9502026-05-29 MEDIUM 5.4 CVE-2026-34507 OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowF… Openclaw 2026.4.29+ Fix from $1,6002026-05-29 HIGH 7.1 CVE-2026-9808 An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured wi… Mitigation only Fix from $1,9502026-05-29 MEDIUM 5.3 CVE-2026-49299 In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined polic… Mitigation only Fix from $1,6002026-05-28 HIGH 8.5 CVE-2026-44850 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber… Portainer 2.33.8 / 2.39.1+ Fix from $1,9502026-05-28 HIGH 8.1 CVE-2026-44882 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber… Portainer 2.33.8+ Fix from $1,9502026-05-28 HIGH 7.7 CVE-2026-46823 Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versio… Public Sector Financials after 12.2.15 Fix from $1,9502026-05-28 MEDIUM 5.3 CVE-2026-42070 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in MantisBT allows users having update… Patch available Fix from $1,6002026-05-28 HIGH 8.1 CVE-2026-44394 An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's… Keystone 27.0.2 / 28.0.2+ Fix from $1,9502026-05-28 HIGH 7.1 CVE-2026-45042 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows cop… Mitigation only Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-42998 An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user … Keystone 27.0.2 / 28.0.2+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-42999 An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON re… Keystone 27.0.2 / 28.0.2+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-43000 An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker wi… Keystone 27.0.2 / 28.0.2+ Fix from $1,9502026-05-28