Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2026-39402 lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an… Lxc 7.0.0+ Fix from $1,6002026-05-05 HIGH 8.2 CVE-2026-39852 Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, … Quarkus 3.20.6.1 / 3.27.3.1+ Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-33489 CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone… Coredns 1.14.3+ Fix from $1,9502026-05-05 HIGH 8.8 CVE-2026-43530 OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution that allow… Openclaw 2026.4.12+ Fix from $1,9502026-05-05 HIGH 7.7 CVE-2026-42438 OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media attachment read helper that allow… Openclaw Patch available Fix from $1,9502026-05-05 HIGH 8.8 CVE-2026-42434 OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying h… Patch available Fix from $1,9502026-05-05 MEDIUM 6.5 CVE-2026-42220 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sens… Nginx Ui 2.3.8+ Fix from $1,6002026-05-04 CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-25293 Buffer overflow due to incorrect authorization in PLC FW Qca7005 Firmware No fix yet Fix from $2,3002026-05-04 MEDIUM 6.5 CVE-2026-43504 An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles … Prosody 0.12.6 / 13.0.5+ Fix from $1,6002026-05-01 HIGH 8.0 CVE-2026-43001 An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-typ… Keystone 27.0.2 / 28.0.2+ Fix from $1,9502026-05-01 MEDIUM 6.4 CVE-2026-41174 Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik'… Traefik 2.11.43 / 3.6.14+ Fix from $1,6002026-04-30 HIGH 8.8 CVE-2026-5712 This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit t… Identityiq 8.3+ Fix from $1,9502026-04-29 HIGH 8.1 CVE-2026-42431 OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of persistent browser profiles. … Openclaw 2026.4.8+ Fix from $1,9502026-04-28 HIGH 7.8 CVE-2026-42432 OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands witho… Openclaw 2026.4.8+ Fix from $1,9502026-04-28 HIGH 8.8 CVE-2026-42426 OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts operator.write scope instead of … Openclaw 2026.4.8+ Fix from $1,9502026-04-28 HIGH 7.1 CVE-2026-42429 OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that escalates identity-be… Openclaw 2026.4.8+ Fix from $1,9502026-04-28 HIGH 8.8 CVE-2026-42422 OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting tokens for unapproved roles. At… Openclaw 2026.4.8+ Fix from $1,9502026-04-28 HIGH 8.8 CVE-2026-41404 OpenClaw before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that allows operator.admin privile… Openclaw 2026.3.31+ Fix from $1,9502026-04-28 MEDIUM 5.4 CVE-2026-41381 OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attackers to bypass channel-level … Openclaw 2026.3.31+ Fix from $1,6002026-04-28 MEDIUM 6.5 CVE-2026-41375 OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce… Openclaw 2026.3.28+ Fix from $1,6002026-04-28 HIGH 7.1 CVE-2026-41379 OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class… Openclaw 2026.3.28+ Fix from $1,9502026-04-28 HIGH 8.5 CVE-2026-41371 OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only s… Openclaw 2026.3.28+ Fix from $1,9502026-04-28 MEDIUM 5.0 CVE-2026-41367 OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions.… Openclaw 2026.3.28+ Fix from $1,6002026-04-28 CRITICAL 9.1 CVE-2026-41248 Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro c… Mitigation only Fix from $2,3002026-04-24 MEDIUM 6.5 CVE-2026-41427 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but… Better Auth\/oauth Provider 1.6.5+ Fix from $1,6002026-04-24 MEDIUM 5.4 CVE-2026-30368 A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integri… Mitigation only Fix from $1,6002026-04-24 CRITICAL 9.8 CVE-2026-25660 CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs … Codechecker 6.27.4+ Fix from $2,3002026-04-24 HIGH 8.1 CVE-2026-23902 Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not… Dolphinscheduler 3.4.1+ Fix from $1,9502026-04-24 HIGH 7.7 CVE-2026-41068 Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalat… Kyverno 1.17.2+ Fix from $1,9502026-04-24