Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.4 CVE-2026-33251 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass vulnerability i… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-20 MEDIUM 5.4 CVE-2026-33291 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators can create Zendesk tickets f… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-20 MEDIUM 5.4 CVE-2026-33312 Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, the `DELETE /api/v1/projects/:… Vikunja 2.2.0+ Fix from $1,6002026-03-20 MEDIUM 5.3 CVE-2026-33132 ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users to bypass organization enforce… Zitadel 3.4.9 / 4.12.3+ Fix from $1,6002026-03-20 HIGH 8.2 CVE-2026-31805 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plu… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,9502026-03-20 HIGH 7.5 CVE-2026-32811 Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC decision API mode with version… Heimdall 0.17.11+ Fix from $1,9502026-03-20 CRITICAL 9.8 CVE-2026-32767 SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextS… Siyuan 3.6.1+ Fix from $2,3002026-03-20 MEDIUM 6.5 CVE-2026-32758 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6… Filebrowser 2.62.0+ Fix from $1,6002026-03-20 MEDIUM 6.5 CVE-2026-32761 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6… Filebrowser 2.62.0+ Fix from $1,6002026-03-20 MEDIUM 5.4 CVE-2026-33410 Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two authorization issues in the cha… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-19 HIGH 7.1 CVE-2026-32035 OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag t… Openclaw 2026.3.2+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-32027 OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly eligible for gro… Openclaw 2026.2.26+ Fix from $1,6002026-03-19 MEDIUM 5.3 CVE-2026-32028 OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-message reaction notifications, al… Openclaw 2026.2.25+ Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-32021 OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist implementation that accepts muta… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 HIGH 7.1 CVE-2026-32023 OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch w… Openclaw 2026.2.24+ Fix from $1,9502026-03-19 MEDIUM 5.4 CVE-2026-32001 OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated with a shared gateway token to … Openclaw 2026.2.22+ Fix from $1,6002026-03-19 HIGH 8.1 CVE-2026-32005 OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block_action, view_submission, a… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 MEDIUM 5.3 CVE-2026-27936 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted … Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-28282 Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-po… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-19 HIGH 8.1 CVE-2026-33302 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `A… Openemr 8.0.0.2+ Fix from $1,9502026-03-19 HIGH 8.6 CVE-2026-31998 OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to all… Openclaw 2026.2.24+ Fix from $1,9502026-03-19 HIGH 8.8 CVE-2026-32693 In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update th… Juju 3.6.19+ Fix from $1,9502026-03-18 MEDIUM 6.5 CVE-2026-22170 OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom config… Openclaw 2026.2.22+ Fix from $1,6002026-03-18 CRITICAL 9.8 CVE-2026-32267EPSS 8% Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, … Craft Cms 4.17.6 / 5.9.12+ Fix from $2,3002026-03-16 MEDIUM 6.5 CVE-2025-69196 FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter… Fastmcp 2.14.2+ Fix from $1,6002026-03-16 MEDIUM 6.6 CVE-2026-2462 Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default ad… Mattermost Server 10.11.11 / 11.2.3+ Fix from $1,6002026-03-16 HIGH 7.5 CVE-2026-32597 PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515… Pyjwt 2.12.0+ Fix from $1,9502026-03-13 MEDIUM 6.5 CVE-2026-32245 Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authori… Tinyauth after 5.0.2 Fix from $1,6002026-03-12 MEDIUM 6.3 CVE-2026-3977 A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. T… Patch available Fix from $1,6002026-03-12 MEDIUM 6.5 CVE-2026-32123 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for gro… Openemr 8.0.0.1+ Fix from $1,6002026-03-11