Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2026-23984 An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only ver… Superset 6.0.0+ Fix from $1,6002026-02-24 MEDIUM 6.5 CVE-2026-23982 An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a d… Superset 6.0.0+ Fix from $1,6002026-02-24 CRITICAL 9.9 CVE-2026-27112 Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the batch resource creation endpoi… Kargo 1.7.8 / 1.8.11+ Fix from $2,3002026-02-20 MEDIUM 6.3 CVE-2026-2819 A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/i… Mitigation only Fix from $1,6002026-02-20 MEDIUM 5.4 CVE-2026-26963 Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit tra… Cilium 1.18.6+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-26328 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authorization could be satisfied by se… Openclaw 2026.2.14+ Fix from $1,6002026-02-20 HIGH 7.5 CVE-2026-26316 OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authentica… Openclaw 2026.2.13+ Fix from $1,9502026-02-19 HIGH 7.1 CVE-2026-26205 opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path`… Patch available Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-26336 Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" en… Alfresco Content Services 25.3+ Fix from $1,9502026-02-19 HIGH 8.8 CVE-2026-25232 Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository col… Gogs 0.14.1+ Fix from $1,9502026-02-19 HIGH 7.8 CVE-2025-4960 The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to m… Mitigation only Fix from $1,9502026-02-19 MEDIUM 6.5 CVE-2026-1999 An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge their own pull request into a r… Enterprise Server 3.17.11 / 3.18.5+ Fix from $1,6002026-02-18 MEDIUM 5.3 CVE-2026-2126 The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versi… Mitigation only Fix from $1,6002026-02-18 HIGH 8.1 CVE-2026-25767 LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels… Lavinmq 2.6.8+ Fix from $1,9502026-02-12 MEDIUM 5.3 CVE-2026-21722 Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one c… Grafana 11.6.10 / 12.1.6+ Fix from $1,6002026-02-12 MEDIUM 5.5 CVE-2026-20624 An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app… macOS 14.8.4 / 15.7.4+ Fix from $1,6002026-02-11 MEDIUM 5.3 CVE-2026-26031 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified… Learning 2.44.0+ Fix from $1,6002026-02-11 MEDIUM 6.5 CVE-2026-26012 vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization mem… Vaultwarden 1.35.3+ Fix from $1,6002026-02-11 HIGH 8.4 CVE-2026-25924 Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an… Kanboard 1.2.50+ Fix from $1,9502026-02-11 CRITICAL 9.8 CVE-2026-25875 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorization middleware trusts client-co… Placipy Mitigation only Fix from $2,3002026-02-09 HIGH 8.1 CVE-2026-25890 File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Pr… Filebrowser 2.57.1+ Fix from $1,9502026-02-09 CRITICAL 9.1 CVE-2026-25811 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier direc… Placipy Mitigation only Fix from $2,3002026-02-09 HIGH 8.8 CVE-2026-2141 A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/ka… Wukong Crm after 11.3.3 Fix from $1,9502026-02-08 MEDIUM 6.5 CVE-2026-2208 A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the compo… Wekan 8.21+ Fix from $1,6002026-02-08 MEDIUM 6.5 CVE-2026-25565 WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than r… Wekan 8.19+ Fix from $1,6002026-02-07 MEDIUM 5.4 CVE-2026-25566 WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without … Wekan 8.19+ Fix from $1,6002026-02-07 HIGH 8.8 CVE-2026-25859 Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resu… Wekan 8.20+ Fix from $1,9502026-02-07 HIGH 7.5 CVE-2026-25561 WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifier… Wekan 8.19+ Fix from $1,9502026-02-07 MEDIUM 6.5 CVE-2026-25729 DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access control vulnerability in the /a… Deepaudit after 3.0.4 Fix from $1,6002026-02-06 HIGH 8.1 CVE-2026-23989 REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud all… Opencloud Reva 2.40.3 / 2.42.3+ Fix from $1,9502026-02-06