Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 8.1 CVE-2025-40897 An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enfor… Mitigation only Fix from $1,9502026-04-15 HIGH 8.8 CVE-2026-40291 Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in th… Chamilo Lms after 1.11.38 Fix from $1,9502026-04-14 MEDIUM 5.4 CVE-2026-24069 Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application… Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.8 CVE-2026-40191 ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta-1f46165, ClearanceKit's End… Mitigation only Fix from $1,6002026-04-10 HIGH 8.1 CVE-2026-35653 OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers wit… Openclaw 2026.3.24+ Fix from $1,9502026-04-10 MEDIUM 6.5 CVE-2026-35657 OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read sco… Openclaw 2026.3.25+ Fix from $1,6002026-04-10 HIGH 7.3 CVE-2026-40224 In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace. Systemd 259.3+ Fix from $1,9502026-04-10 MEDIUM 5.3 CVE-2026-33551 An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create … Keystone 26.1.1+ Fix from $1,6002026-04-10 MEDIUM 5.4 CVE-2026-2712 The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat… Mitigation only Fix from $1,6002026-04-10 HIGH 8.8 CVE-2026-35645 OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a sy… Openclaw 2026.3.25+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-35635 OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse mu… Openclaw 2026.3.22+ Fix from $1,6002026-04-09 HIGH 8.1 CVE-2026-34512 OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authe… Openclaw 2026.3.25+ Fix from $1,9502026-04-09 MEDIUM 5.4 CVE-2026-40071 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abo… Pyload 2026-04-13+ Fix from $1,6002026-04-09 MEDIUM 6.5 CVE-2026-33461 Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user with limited Fleet privileges … Kibana 8.19.14 / 9.2.8+ Fix from $1,6002026-04-08 HIGH 8.8 CVE-2026-27140 SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer… Go 1.25.9 / 1.26.2+ Fix from $1,9502026-04-08 HIGH 8.1 CVE-2026-39331 ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper a… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 7.1 CVE-2026-22682 OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling i… Patch available Fix from $1,9502026-04-07 MEDIUM 6.8 CVE-2026-35586 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_con… Pyload Ng after 0.5.0b3.dev96 Fix from $1,6002026-04-07 HIGH 8.1 CVE-2026-35604 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Filebrowser 2.63.1+ Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2026-35490 changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (… Changedetection 0.54.8+ Fix from $2,3002026-04-07 MEDIUM 6.1 CVE-2026-35491 FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, Pi-hole FTL suppor… Ftldns 6.6+ Fix from $1,6002026-04-07 MEDIUM 5.3 CVE-2026-5380 An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an… Runzero Platform 4.0.260204.2+ Fix from $1,6002026-04-07 MEDIUM 5.8 CVE-2026-5384 An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is… Runzero Platform 4.0.26021.0+ Fix from $1,6002026-04-07 MEDIUM 5.8 CVE-2026-5374 An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. Thi… Runzero Platform 4.0.260202.0+ Fix from $1,6002026-04-07 MEDIUM 6.8 CVE-2026-5378 An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance… Runzero Platform 4.0.260203.0+ Fix from $1,6002026-04-07 HIGH 7.5 CVE-2026-35464 pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin us… Pyload 2026-04-02+ Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2026-28808 Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when se… Erlang\/inets 9.1.0.6 / 9.3.2.4+ Fix from $2,3002026-04-07 HIGH 8.1 CVE-2026-35412 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tu… Directus 11.16.1+ Fix from $1,9502026-04-06 HIGH 8.1 CVE-2026-35442 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields w… Directus 11.17.0+ Fix from $1,9502026-04-06 HIGH 8.8 CVE-2026-34972 OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1… Helm Charts 0.2.62 / 1.14.0+ Fix from $1,9502026-04-06