Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.3 CVE-2026-34660 Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code… Connect Desktop Application after 2025.9.15 Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-2465 Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR… Mitigation only Fix from $1,9502026-05-12 HIGH 8.1 CVE-2026-43913 Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the enti… Vaultwarden 1.35.5+ Fix from $1,9502026-05-11 MEDIUM 6.5 CVE-2026-43889 Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both collectionId and documentId simu… Mitigation only Fix from $1,6002026-05-11 HIGH 7.8 CVE-2026-28951 An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, m… Ipados 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28873 This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app ma… Ipados 18.7.9 / 26.4+ Fix from $1,9502026-05-11 CRITICAL 9.4 CVE-2026-42882 oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path inte… Patch available Fix from $2,3002026-05-11 MEDIUM 6.5 CVE-2026-42883 Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpoint validates that the reques… Mitigation only Fix from $1,6002026-05-11 MEDIUM 5.3 CVE-2026-45002 OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-i… Openclaw 2026.4.20+ Fix from $1,6002026-05-11 MEDIUM 5.4 CVE-2026-44998 OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions. … Openclaw 2026.4.20+ Fix from $1,6002026-05-11 MEDIUM 6.8 CVE-2026-42312 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SE… Pyload Ng 0.5.0b3.dev100+ Fix from $1,6002026-05-11 HIGH 8.3 CVE-2026-42313 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SE… Pyload Ng 0.5.0b3.dev100+ Fix from $1,9502026-05-11 HIGH 8.8 CVE-2026-42843 Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system mana… Grav Plugin Api No fix yet Fix from $1,9502026-05-11 HIGH 8.1 CVE-2026-42349 Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @cler… Clerk\/astro 1.7.79 / 2.1.6+ Fix from $1,9502026-05-11 MEDIUM 6.5 CVE-2026-42610 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass th… Grav after 1.8.0 Fix from $1,6002026-05-11 HIGH 7.2 CVE-2025-9973 Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication … Identity Server 7.1.0.26+ Fix from $1,9502026-05-11 HIGH 7.3 CVE-2025-10908 Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass… Identity Server 6.0.0.249 / 6.1.0.248+ Fix from $1,9502026-05-11 CRITICAL 9.0 CVE-2026-42571 Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.2… Patch available Fix from $2,3002026-05-09 MEDIUM 6.5 CVE-2025-15633 An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (… Bigfix Webui Api 14 / 22+ Fix from $1,6002026-05-09 HIGH 8.1 CVE-2026-42296 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, … Argo Workflows 3.7.14 / 4.0.5+ Fix from $1,9502026-05-09 MEDIUM 6.5 CVE-2026-42137 Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not… Kirby 4.9.0 / 5.4.0+ Fix from $1,6002026-05-09 HIGH 8.2 CVE-2026-41432 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability ex… New Api 0.12.10+ Fix from $1,9502026-05-08 CRITICAL 10.0 CVE-2026-42160 Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before v… Mitigation only Fix from $2,3002026-05-08 MEDIUM 6.5 CVE-2025-66170 The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in … Cloudstack 4.22.0.1+ Fix from $1,6002026-05-08 HIGH 7.4 CVE-2026-40213 OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any … Mitigation only Fix from $1,9502026-05-07 MEDIUM 5.4 CVE-2026-41903 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user holding the PERM_EDIT_USERS permi… Mitigation only Fix from $1,6002026-05-07 MEDIUM 6.0 CVE-2026-41689 Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notification feature reuses an admini… Mitigation only Fix from $1,6002026-05-07 HIGH 7.1 CVE-2026-41660 Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authentication reset inverts the au… Mitigation only Fix from $1,9502026-05-07 HIGH 8.8 CVE-2026-44110 OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that trusts DM pairing-store en… Openclaw 2026.4.15+ Fix from $1,9502026-05-06 MEDIUM 6.8 CVE-2026-6863 Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with only the reader role in the root… Mitigation only Fix from $1,6002026-05-06