Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.2 CVE-2026-29182 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.4 and 9.4.1-alpha.3, Pa… Parse Server 8.6.4+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-29087 @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving togeth… Node Server 1.19.10+ Fix from $1,9502026-03-06 HIGH 8.1 CVE-2026-23925 An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can le… Zabbix 6.0.41 / 7.0.18+ Fix from $1,9502026-03-06 MEDIUM 6.5 CVE-2026-28715 Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows)… Cyber Protect 17.0.41186+ Fix from $1,6002026-03-06 HIGH 8.1 CVE-2026-28473 OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec ap… Openclaw 2026.2.2+ Fix from $1,9502026-03-05 CRITICAL 9.8 CVE-2026-28474 OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist valid… Openclaw 2026.2.6+ Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2026-28466 OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke par… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28392 OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any … Openclaw 2026.2.14+ Fix from $2,3002026-03-05 HIGH 7.5 CVE-2026-28790 OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to term… Olivetin 3000.11.0+ Fix from $1,9502026-03-05 MEDIUM 5.3 CVE-2026-21621 Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privilege Escalation. An API key cr… Hexpm 2026-03-05+ Fix from $1,6002026-03-05 HIGH 8.1 CVE-2026-3009 A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even… Build Of Keycloak Mitigation only Fix from $1,9502026-03-05 HIGH 7.8 CVE-2026-29127 The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured w… Sfx2100 Firmware No fix yet Fix from $1,9502026-03-05 HIGH 7.8 CVE-2026-29126 Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver al… Sfx2100 Firmware No fix yet Fix from $1,9502026-03-05 HIGH 8.3 CVE-2026-27802 Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privile… Vaultwarden 1.35.4+ Fix from $1,9502026-03-04 HIGH 8.3 CVE-2026-27803 Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has… Vaultwarden 1.35.4+ Fix from $1,9502026-03-04 HIGH 7.8 CVE-2026-26949 Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local … Device Management Agent 26.02+ Fix from $1,9502026-03-04 MEDIUM 5.4 CVE-2026-3103 A logic error in the remove_password() function in Checkmk GmbH's Checkmk versions <2.4.0p23, <2.3.0p43, and 2.2.0 (EOL) allows a low-privileged user… Checkmk Mitigation only Fix from $1,6002026-03-04 MEDIUM 5.4 CVE-2025-13734 IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized acces… Engineering Requirements Management Doors Next Mitigation only Fix from $1,6002026-03-03 CRITICAL 9.8 CVE-2026-3136 An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execut… Cloud Build 2026-1-26+ Fix from $2,3002026-03-03 MEDIUM 6.5 CVE-2026-28354 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws,… Clipbucket 5.5.3-59+ Fix from $1,6002026-02-27 CRITICAL 9.8 CVE-2026-2293 A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization optio… Nest Mitigation only Fix from $2,3002026-02-27 MEDIUM 6.5 CVE-2025-9572 n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, … Satellite 3.16.2+ Fix from $1,6002026-02-27 MEDIUM 6.7 CVE-2026-27653 The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary … Securebrowser For Onegate 1.4.8 / 2.0.15+ Fix from $1,6002026-02-27 HIGH 7.1 CVE-2026-25741 Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card updat… Patch available Fix from $1,9502026-02-26 HIGH 7.5 CVE-2026-26265 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items en… Discourse 2025.12.0 / 2026.1.1+ Fix from $1,9502026-02-26 MEDIUM 6.5 CVE-2026-25963 Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion A… Fleet 4.80.1+ Fix from $1,6002026-02-26 HIGH 8.8 CVE-2026-27899 WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-ad… Wireguard Portal 2.1.3+ Fix from $1,9502026-02-26 MEDIUM 6.5 CVE-2026-24487 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization byp… Openemr 8.0.0+ Fix from $1,6002026-02-25 CRITICAL 9.1 CVE-2026-27607 RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy condi… Rustfs Mitigation only Fix from $2,3002026-02-25 MEDIUM 6.5 CVE-2026-25127 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not … Openemr 8.0.0+ Fix from $1,6002026-02-25