Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.3 CVE-2026-45297 OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_… Mitigation only Fix from $1,6002026-05-28 HIGH 8.1 CVE-2026-48064 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is configured with deny_remote=… No fix yet Fix from $1,9502026-05-27 HIGH 8.4 CVE-2026-45108 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, Himmelblau contained an authe… Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.1 CVE-2026-44681 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's O… Authlib 1.6.12+ Fix from $1,6002026-05-27 MEDIUM 5.3 CVE-2026-6713 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that und… GitLab 18.10.7 / 18.11.4+ Fix from $1,6002026-05-27 HIGH 8.1 CVE-2026-48152 Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by generic TABLE READ, not by Bui… Mitigation only Fix from $1,9502026-05-27 MEDIUM 5.4 CVE-2026-45718 Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:sourceId/actions/:actionId/trigger)… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.5 CVE-2026-45081 Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave … Mitigation only Fix from $1,6002026-05-27 HIGH 7.1 CVE-2026-44473 Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupRespons… Mitigation only Fix from $1,9502026-05-27 CRITICAL 10.0 CVE-2026-44330 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanagement route group without inbo… Free5gc 4.2.2+ Fix from $2,3002026-05-27 HIGH 8.1 CVE-2026-44838 RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular e… Rabbitmq Server 4.2.4+ Fix from $1,9502026-05-27 HIGH 7.1 CVE-2026-42280 Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return u… Auth0.js 10.0.0+ Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-9603 A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/dele… No fix yet Fix from $1,6002026-05-26 HIGH 8.8 CVE-2026-44832 Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own priv… Snipe It 8.4.1+ Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2026-3660 IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that woul… Engineering Lifecycle Management Mitigation only Fix from $2,3002026-05-26 HIGH 8.1 CVE-2026-8046 The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this … Mitigation only Fix from $1,9502026-05-26 HIGH 7.3 CVE-2026-9350 A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/app… Mitigation only Fix from $1,9502026-05-24 HIGH 8.8 CVE-2018-25353 Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension b… No fix yet Fix from $1,9502026-05-23 HIGH 8.8 CVE-2026-6406 The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket m… Docker Desktop 4.59.0+ Fix from $1,9502026-05-22 MEDIUM 6.5 CVE-2026-39966 TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions to any authenticated user who … Patch available Fix from $1,6002026-05-22 HIGH 7.1 CVE-2026-40166 authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with a… Mitigation only Fix from $1,9502026-05-22 MEDIUM 5.4 CVE-2026-28735 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback … Mattermost Server 10.11.15 / 11.4.5+ Fix from $1,6002026-05-22 CRITICAL 10.0 CVE-2026-46595 Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than pu… Crypto 0.52.0+ Fix from $2,3002026-05-22 HIGH 8.8 CVE-2026-8350 Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Adminis… Concrete Cms after 9.5.0 Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-47101 LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generat… Litellm 1.83.14+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-47102 LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to u… Litellm 1.83.10+ Fix from $1,9502026-05-21 MEDIUM 6.5 CVE-2026-20238 In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that … Ai Toolkit 5.7.3+ Fix from $1,6002026-05-20 MEDIUM 5.3 CVE-2026-34579 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization Bypass through the private i… Patch available Fix from $1,6002026-05-19 MEDIUM 5.7 CVE-2026-34600 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic er… Patch available Fix from $1,6002026-05-19 MEDIUM 5.3 CVE-2026-42526 In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic coul… Apache Airflow Providers Amazon 9.28.0+ Fix from $1,6002026-05-19