Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.9 CVE-2026-41470 LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Sessi… Mitigation only Fix from $1,6002026-05-19 HIGH 8.8 CVE-2026-42096 Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privi… Pro Cloud Server after 6.1.167 Fix from $1,9502026-05-19 HIGH 7.3 CVE-2026-44567 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the API does not properly valida… Open Webui 0.1.124+ Fix from $1,9502026-05-15 HIGH 8.8 CVE-2026-45672 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the /api/v1/utils/code/execute en… Open Webui 0.8.12+ Fix from $1,9502026-05-15 MEDIUM 5.4 CVE-2026-44564 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the ydoc:document:update Socket.IO… Open Webui 0.9.0+ Fix from $1,6002026-05-15 MEDIUM 6.5 CVE-2026-45339 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restri… Open Webui 0.9.0+ Fix from $1,6002026-05-15 MEDIUM 5.4 CVE-2026-44561 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the is_user_channel_member functio… Open Webui 0.9.0+ Fix from $1,6002026-05-15 MEDIUM 6.5 CVE-2026-46362 phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate… Mitigation only Fix from $1,6002026-05-15 HIGH 7.5 CVE-2026-46366 phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing … Mitigation only Fix from $1,9502026-05-15 HIGH 8.1 CVE-2026-44633 Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allow… Mitigation only Fix from $1,9502026-05-14 MEDIUM 6.5 CVE-2026-41888 Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag>… Distribution 3.1.1+ Fix from $1,6002026-05-14 MEDIUM 6.5 CVE-2026-42572 Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a missing authorization direct… Hatchet 0.83.39+ Fix from $1,6002026-05-14 HIGH 8.8 CVE-2025-15023 Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Au… Mitigation only Fix from $1,9502026-05-14 HIGH 7.1 CVE-2026-32991 Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account. Mitigation only Fix from $1,9502026-05-13 HIGH 7.2 CVE-2026-44380 MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key … Misp 2.5.37+ Fix from $1,9502026-05-13 CRITICAL 9.1 CVE-2026-42032 CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastor… Ckan 2.10.10 / 2.11.5+ Fix from $2,3002026-05-13 CRITICAL 9.9 CVE-2026-43999 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (includi… Vm2 3.11.0+ Fix from $2,3002026-05-13 HIGH 7.5 CVE-2026-44573 Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router … Next.js 15.5.16 / 16.2.5+ Fix from $1,9502026-05-13 CRITICAL 9.9 CVE-2026-41050 Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored… Mitigation only Fix from $2,3002026-05-13 MEDIUM 5.3 CVE-2026-2725 Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permis… Gerrit Patch available Fix from $1,6002026-05-13 HIGH 7.1 CVE-2026-45226 Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflow… Patch available Fix from $1,9502026-05-12 HIGH 8.1 CVE-2026-44260 efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modific… Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.9 CVE-2026-43948 wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a … Mitigation only Fix from $2,3002026-05-12 MEDIUM 5.7 CVE-2026-33570 PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational perm… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.3 CVE-2026-35555 PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of pro… Mitigation only Fix from $1,6002026-05-12 HIGH 8.2 CVE-2026-26289 PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information … Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.0 CVE-2026-44221 ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific data… Patch available Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-42889 Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebS… Mitigation only Fix from $2,3002026-05-12 HIGH 7.5 CVE-2026-34645 Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulne… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-34646 Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulne… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502026-05-12