Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.0 CVE-2026-71201 In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased b… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.0 CVE-2026-71191 In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned UR… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.0 CVE-2026-71192 In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API… No fix yet Fix from $1,6002026-08-05 HIGH 7.1 CVE-2026-55707 In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard … No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-70494 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handl… No fix yet Fix from $1,9502026-08-04 MEDIUM 6.3 CVE-2026-70490 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backen… No fix yet Fix from $1,6002026-08-04 HIGH 7.1 CVE-2026-70471 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the co… No fix yet Fix from $1,9502026-08-04 HIGH 7.1 CVE-2026-70472 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpo… No fix yet Fix from $1,9502026-08-04 HIGH 7.6 CVE-2026-70474 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credenti… No fix yet Fix from $1,9502026-08-04 HIGH 7.1 CVE-2026-69262 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized re… No fix yet Fix from $1,9502026-08-04 MEDIUM 5.3 CVE-2026-64630 A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. No fix yet Fix from $1,6002026-08-04 MEDIUM 6.3 CVE-2026-18773 A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gate… No fix yet Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-62927 In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating author… Milo 1.1.5+ Fix from $1,9502026-08-04 CRITICAL 9.8 CVE-2026-48333 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exp… Campaign after 7.4.2 Fix from $2,3002026-08-03 HIGH 8.5 CVE-2026-48113 Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL r… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.1 CVE-2026-68980 Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor… Nifi 2.11.0+ Fix from $2,3002026-08-03 MEDIUM 6.5 CVE-2026-58139 The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to e… No fix yet Fix from $1,6002026-08-03 HIGH 7.7 CVE-2026-62354 Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit propo… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.5 CVE-2026-68930 Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were n… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.5 CVE-2026-15254 The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing short… No fix yet Fix from $1,6002026-08-03 HIGH 8.1 CVE-2026-68581 Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independen… No fix yet Fix from $1,9502026-08-02 MEDIUM 6.5 CVE-2026-18572 Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing… Build Of Keycloak No fix yet Fix from $1,6002026-08-02 HIGH 7.5 CVE-2026-16540 The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own rec… No fix yet Fix from $1,9502026-08-02 MEDIUM 5.4 CVE-2026-16064 The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when qui… No fix yet Fix from $1,6002026-08-02 CRITICAL 9.8 CVE-2026-67341 ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with … No fix yet Fix from $2,3002026-08-01 MEDIUM 5.4 CVE-2026-67310 OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of … No fix yet Fix from $1,6002026-08-01 MEDIUM 6.5 CVE-2026-2411 Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to … Zephyr 4.5.0+ Fix from $1,6002026-08-01 HIGH 7.4 CVE-2026-18394 Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured v… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.4 CVE-2026-54707 OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Pri… No fix yet Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-18203 A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend p… Build Of Keycloak No fix yet Fix from $1,6002026-07-31