Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.1 CVE-2026-72630 Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to m… No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-73652 vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.1 CVE-2026-58443 Public-only repository tokens can update private PR head branches No fix yet Fix from $5,7502026-08-13 MEDIUM 6.5 CVE-2026-57897 Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-58416 Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-58427 Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-55987 OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) No fix yet Fix from $4,9002026-08-13 CRITICAL 9.6 CVE-2026-56443 Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 No fix yet Fix from $5,7502026-08-13 HIGH 8.1 CVE-2026-24791 Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-70463 rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when sp… No fix yet Fix from $4,9002026-08-13 HIGH 7.4 CVE-2026-70452 rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS … No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-53786 rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supp… No fix yet Fix from $4,0002026-08-13 HIGH 8.8 CVE-2026-49473 @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by ma… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.6 CVE-2026-71193 In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the targe… No fix yet Fix from $5,7502026-08-12 HIGH 7.1 CVE-2026-73499 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permissi… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72788 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator wo… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72792 SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts f… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.9 CVE-2026-63296 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When m… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-63297 An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target proj… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-62420 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project ins… No fix yet Fix from $5,7502026-08-12 HIGH 8.5 CVE-2026-15423 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under … No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-73286 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request he… No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-73289 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifie… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-73290 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/ac… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-73265 RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadP… No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-73285 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTF… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.7 CVE-2026-18171 Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge g… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-47230 Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same ro… No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-47231 Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking tha… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-47227 Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …… No fix yet Fix from $4,0002026-08-12