Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.3 CVE-2026-3525 Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated)… File Access Fix 8.x-1.2+ Fix from $1,6002026-03-26 MEDIUM 5.3 CVE-2026-3526 Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated)… File Access Fix 8.x-1.2+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33469 Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an authenticated non-admin user can… Frigate No fix yet Fix from $1,6002026-03-26 MEDIUM 5.2 CVE-2026-33015 EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop (StopTransaction), the EVSE c… Everest 2026.02.0+ Fix from $1,6002026-03-26 MEDIUM 5.2 CVE-2026-33014 EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorization response restores `author… Everest 2026.02.0+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-29044 EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the TransactionStarted event, Au… Everest 2026.02.0+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33343 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with R… Etcd 3.4.42 / 3.5.28+ Fix from $1,6002026-03-26 MEDIUM 5.4 CVE-2026-4274 Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing memb… Mattermost Server 10.11.11 / 11.2.3+ Fix from $1,6002026-03-26 MEDIUM 6.9 CVE-2026-4263 Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter  'visi… Mitigation only Fix from $1,6002026-03-26 MEDIUM 6.9 CVE-2026-4262 Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'ID' i… Mitigation only Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33217 NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs… Nats Server 2.11.15 / 2.12.6+ Fix from $1,6002026-03-25 MEDIUM 5.3 CVE-2026-33722 n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external s… N8n 1.123.23 / 2.6.4+ Fix from $1,6002026-03-25 MEDIUM 5.3 CVE-2026-3210 Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icons: from 0.0.0 before 2.0.4. Material Icons 2.0.4+ Fix from $1,6002026-03-25 HIGH 7.1 CVE-2026-33330 FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integrati… Filerise 3.10.0+ Fix from $1,9502026-03-24 MEDIUM 6.5 CVE-2026-33421 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.53 and 9.6.0-alpha.42, … Parse Server 8.6.53 / 9.6.0+ Fix from $1,6002026-03-24 HIGH 8.1 CVE-2026-33668 Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disable… Vikunja 2.2.1+ Fix from $1,9502026-03-24 MEDIUM 6.5 CVE-2026-33676 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tasks, it populates the `related… Vikunja 2.2.1+ Fix from $1,6002026-03-24 HIGH 8.1 CVE-2026-33316 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled user… Vikunja 2.2.0+ Fix from $1,9502026-03-24 MEDIUM 5.4 CVE-2026-28755 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when c… Nginx Plus 1.28.3 / 1.29.7+ Fix from $1,6002026-03-24 HIGH 8.8 CVE-2026-4639 Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform cert… Vitalsesp after 6.3 Fix from $1,9502026-03-24 MEDIUM 5.3 CVE-2026-27183 OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attacker… Openclaw 2026.3.7+ Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2026-27646 OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to ini… Openclaw 2026.3.7+ Fix from $1,6002026-03-23 HIGH 7.6 CVE-2026-33650 WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" permission can escalate privil… Avideo after 26.0 Fix from $1,9502026-03-23 HIGH 8.1 CVE-2026-32067 OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing pol… Openclaw 2026.2.26+ Fix from $1,9502026-03-21 MEDIUM 5.4 CVE-2026-32895 OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized … Openclaw 2026.2.26+ Fix from $1,6002026-03-21 MEDIUM 6.5 CVE-2026-32058 OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of p… Openclaw 2026.2.26+ Fix from $1,6002026-03-21 HIGH 8.8 CVE-2026-32051 OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to in… Openclaw 2026.3.1+ Fix from $1,9502026-03-21 MEDIUM 5.3 CVE-2026-32050 OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized sender… Openclaw 2026.2.25+ Fix from $1,6002026-03-21 HIGH 8.8 CVE-2026-32042 OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pa… Openclaw 2026.2.25+ Fix from $1,9502026-03-21 MEDIUM 6.5 CVE-2026-33428 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staff user with elevated group me… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-21