Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.3 CVE-2026-32101 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.3.1, the S3 storage manager's isAuthorized() functi… Studiocms 0.3.1+ Fix from $1,6002026-03-11 MEDIUM 6.5 CVE-2026-32102 OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution e… Olivetin after 3000.10.2 Fix from $1,6002026-03-11 MEDIUM 6.5 CVE-2026-32108 Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-option). This vulne… Copyparty 1.20.12+ Fix from $1,6002026-03-11 HIGH 7.5 CVE-2026-31887 Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows… Shopware 6.6.10.15 / 6.7.8.1+ Fix from $1,9502026-03-11 HIGH 7.1 CVE-2026-30239 OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned… Openproject 17.2.0+ Fix from $1,9502026-03-11 MEDIUM 6.5 CVE-2026-1471 Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the conte… Neo4j 5.26.22 / 2026.01.4+ Fix from $1,6002026-03-11 CRITICAL 9.8 CVE-2026-1524 An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c… Neo4j 5.26.22 / 2026.02+ Fix from $2,3002026-03-11 HIGH 8.1 CVE-2026-31892 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.1… Argo Workflows 3.7.11 / 4.0.2+ Fix from $1,9502026-03-11 HIGH 7.5 CVE-2026-28229 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow … Argo Workflows 3.7.11 / 4.0.2+ Fix from $1,9502026-03-11 HIGH 7.2 CVE-2026-1497 Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following … Neo4j 5.26.22 / 2026.02+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-32059 OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviati… Openclaw 2026.2.23+ Fix from $1,9502026-03-11 HIGH 7.5 CVE-2026-21309 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vuln… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502026-03-11 MEDIUM 5.3 CVE-2026-21286 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vuln… Commerce B2b 1.3.3 / 2.4.4+ Fix from $1,6002026-03-11 HIGH 7.5 CVE-2026-21289 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vuln… Commerce B2b 1.3.3 / 2.4.4+ Fix from $1,9502026-03-11 MEDIUM 5.3 CVE-2026-31838 Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header mat… Istio 1.27.8 / 1.28.5+ Fix from $1,6002026-03-10 HIGH 7.7 CVE-2026-31801 zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0 to 2.1.14, zot’s dist-spec a… Zot 2.1.15+ Fix from $1,9502026-03-10 CRITICAL 9.1 CVE-2026-30965 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerab… Parse Server 8.6.21 / 9.5.2+ Fix from $2,3002026-03-10 HIGH 7.5 CVE-2026-30947 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.3 and 8.6.16, class-leve… Parse Server 8.6.16 / 9.5.2+ Fix from $1,9502026-03-10 HIGH 8.2 CVE-2026-26308 Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filte… Envoy 1.34.13 / 1.35.8+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-30944 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoi… Studiocms 0.4.0+ Fix from $1,9502026-03-10 HIGH 7.1 CVE-2026-30945 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens… Studiocms 0.4.0+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26141 Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. Azure Automation Hybrid Worker Windows Extension 1.3.74+ Fix from $1,9502026-03-10 HIGH 7.1 CVE-2026-28513 Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects… Pocket Id 2.4.0+ Fix from $1,9502026-03-10 CRITICAL 9.8 CVE-2026-30863 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, … Parse Server 8.6.10 / 9.5.0+ Fix from $2,3002026-03-07 MEDIUM 5.3 CVE-2026-30854 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3.1-alpha.3 to before version … Parse Server 9.5.0+ Fix from $1,6002026-03-07 MEDIUM 6.5 CVE-2026-29195 Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lacks validation to prevent an ad… Netmaker 1.5.0+ Fix from $1,6002026-03-07 HIGH 8.1 CVE-2026-29194 Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validates host JWT tokens. When a ro… Netmaker 1.5.0+ Fix from $1,9502026-03-07 HIGH 8.8 CVE-2026-30820 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that… Flowise 3.0.13+ Fix from $1,9502026-03-07 HIGH 8.2 CVE-2026-30241 Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDepth limit on GraphQL subscripti… Mercurius 16.8.0+ Fix from $1,9502026-03-06 HIGH 7.2 CVE-2026-30229 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.6 and 9.5.0-alpha.4, th… Parse Server 8.6.6+ Fix from $1,9502026-03-06