Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 8.8 CVE-2026-35029EPSS 26% LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce a… Litellm 1.83.0+ Fix from $1,9502026-04-06 CRITICAL 9.1 CVE-2026-5574 A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBr… Hi Led Wr120 G2 Firmware No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2026-34953 PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal … Praisonai 4.5.97+ Fix from $2,3002026-04-03 MEDIUM 6.3 CVE-2026-27447 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd… Cups after 2.4.16 Fix from $1,6002026-04-03 MEDIUM 6.5 CVE-2025-68153 Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special ope… Juju after 3.6.18 Fix from $1,6002026-04-03 CRITICAL 9.8 CVE-2026-33105 Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Azure Kubernetes Service Mitigation only Fix from $2,3002026-04-03 HIGH 7.5 CVE-2026-32173 Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. Azure Sre Agent Mitigation only Fix from $1,9502026-04-03 CRITICAL 9.8 CVE-2026-32213 Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-04-03 HIGH 7.5 CVE-2026-34376 PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.0, an access-con… Pdfding 1.7.0+ Fix from $1,9502026-04-01 HIGH 8.8 CVE-2025-71278 XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version … Xenforo 2.3.5+ Fix from $1,9502026-04-01 HIGH 7.5 CVE-2026-34453 SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected docum… Siyuan 3.6.2+ Fix from $1,9502026-03-31 MEDIUM 6.5 CVE-2026-34586 PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.1, check_shared_… Pdfding 1.7.1+ Fix from $1,6002026-03-31 HIGH 8.1 CVE-2026-32726 SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authoriz… Scitokens Cpp Library 1.4.1+ Fix from $1,9502026-03-31 CRITICAL 9.1 CVE-2026-34532 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, … Parse Server 8.6.67 / 9.7.0+ Fix from $2,3002026-03-31 MEDIUM 6.5 CVE-2026-33576 OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can forc… Openclaw 2026.3.28+ Fix from $1,6002026-03-31 HIGH 8.1 CVE-2026-33577 OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operato… Openclaw 2026.3.28+ Fix from $1,9502026-03-31 CRITICAL 9.9 CVE-2026-33579 OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into th… Openclaw 2026.3.28+ Fix from $2,3002026-03-31 MEDIUM 6.5 CVE-2026-24029 When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the AC… Dnsdist 1.9.12 / 2.0.3+ Fix from $1,6002026-03-31 HIGH 8.3 CVE-2026-0562 A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging… Lollms after 2.1.0 Fix from $1,9502026-03-29 HIGH 7.1 CVE-2026-32972 OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to acce… Openclaw 2026.3.11+ Fix from $1,9502026-03-29 HIGH 7.5 CVE-2026-32978 OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain scri… Openclaw 2026.3.11+ Fix from $1,9502026-03-29 HIGH 8.4 CVE-2026-32918 OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent… Openclaw 2026.3.11+ Fix from $1,9502026-03-29 MEDIUM 6.1 CVE-2026-32919 OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attac… Openclaw 2026.3.11+ Fix from $1,6002026-03-29 MEDIUM 5.4 CVE-2026-32923 OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails to enforce member users and r… Openclaw 2026.3.11+ Fix from $1,6002026-03-29 CRITICAL 9.8 CVE-2026-32924 OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p… Openclaw 2026.3.12+ Fix from $2,3002026-03-29 HIGH 8.8 CVE-2026-32914 OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-author… Openclaw 2026.3.12+ Fix from $1,9502026-03-29 HIGH 8.8 CVE-2026-32915 OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolv… Openclaw 2026.3.11+ Fix from $1,9502026-03-29 MEDIUM 5.3 CVE-2026-34364 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category lis… Avideo after 26.0 Fix from $1,6002026-03-27 HIGH 7.5 CVE-2026-4933 Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions… Unpublished Node Permissions 8.x-1.7+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-3573 Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affects AI (Artificial Intelligence… Artificial Intelligence 1.1.11 / 1.2.12+ Fix from $1,9502026-03-26