Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.2 CVE-2026-13738 CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to res… No fix yet Fix from $5,7502026-08-11 HIGH 8.6 CVE-2025-30238 In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged oper… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.9 CVE-2026-72886 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/… No fix yet Fix from $5,7502026-08-10 HIGH 8.8 CVE-2026-69118 Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execut… No fix yet Fix from $4,9002026-08-10 MEDIUM 6.9 CVE-2026-21076 Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. No fix yet Fix from $4,0002026-08-10 MEDIUM 6.9 CVE-2026-21077 Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. No fix yet Fix from $4,0002026-08-10 MEDIUM 5.5 CVE-2026-18934 The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named … No fix yet Fix from $4,0002026-08-10 MEDIUM 5.3 CVE-2026-15229 The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated user… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.3 CVE-2026-19350 A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component Ta… No fix yet Fix from $4,0002026-08-09 MEDIUM 6.5 CVE-2026-19345 A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manip… No fix yet Fix from $4,0002026-08-09 HIGH 7.1 CVE-2026-45808 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A t… No fix yet Fix from $1,9502026-08-07 HIGH 8.2 CVE-2026-17594 Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user in… No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-66059 Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. … No fix yet Fix from $1,6002026-08-07 MEDIUM 5.9 CVE-2026-37171 A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, da… No fix yet Fix from $1,6002026-08-07 HIGH 7.8 CVE-2026-7867 A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option … No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-71433 LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the … No fix yet Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-48076 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.1 CVE-2026-47185 Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authent… No fix yet Fix from $1,6002026-08-06 HIGH 8.5 CVE-2026-45414 Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to th… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-64640 Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permissi… Polaris after 1.6.0 Fix from $1,6002026-08-06 HIGH 7.3 CVE-2026-19010 A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the c… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-19006 A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Gg… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18997 A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18992 A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/exec… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.8 CVE-2026-52466 Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming requ… No fix yet Fix from $2,3002026-08-06 HIGH 8.2 CVE-2026-71315 Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-f… No fix yet Fix from $1,9502026-08-05 MEDIUM 5.5 CVE-2026-18954 Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP clie… Documentdb Mcp Server 1.0.12+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-50749 Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary… Answer 2.0.2+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-71247 Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields b… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-71234 Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) a… No fix yet Fix from $1,9502026-08-05