Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.3 CVE-2026-62323 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI acc… No fix yet Fix from $1,6002026-07-31 HIGH 7.1 CVE-2026-55502 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even … No fix yet Fix from $1,9502026-07-31 HIGH 7.7 CVE-2026-14538 An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1… Mcp Toolbox For Databases after 1.4.0 Fix from $1,9502026-07-31 CRITICAL 9.8 CVE-2026-14537 Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated at… Mcp Toolbox For Databases No fix yet Fix from $2,3002026-07-31 MEDIUM 6.6 CVE-2026-65835 Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResour… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.8 CVE-2026-67347 Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-location.service.ts and asset.se… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-41187 Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy,… Calico 3.21.7 / 3.22.4+ Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-14923 The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and u… No fix yet Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2026-48449 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of … Campaign after 7.4.2 Fix from $2,3002026-07-30 MEDIUM 6.5 CVE-2026-65975 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.… Pydantic Ai 1.107.1 / 2.5.0+ Fix from $1,6002026-07-29 MEDIUM 5.3 CVE-2026-6336 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under … GitLab 19.0.5 / 19.1.3+ Fix from $1,6002026-07-29 CRITICAL 9.3 CVE-2026-18236 A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or in… No fix yet Fix from $2,3002026-07-29 HIGH 8.2 CVE-2026-54693 ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email … No fix yet Fix from $1,9502026-07-29 HIGH 7.2 CVE-2026-18255 A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a membe… No fix yet Fix from $1,9502026-07-29 HIGH 8.5 CVE-2026-44944 An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects… No fix yet Fix from $1,9502026-07-29 HIGH 8.2 CVE-2026-58159 Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2025-10656 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions u… No fix yet Fix from $2,3002026-07-29 MEDIUM 5.3 CVE-2026-66064 goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened f… No fix yet Fix from $1,6002026-07-28 HIGH 7.5 CVE-2026-54719 goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?… No fix yet Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-48390 Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerabili… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 HIGH 8.6 CVE-2026-48396 Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An a… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 MEDIUM 6.5 CVE-2026-7868 IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrat… No fix yet Fix from $1,6002026-07-28 HIGH 8.8 CVE-2026-14167 A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management du… No fix yet Fix from $1,9502026-07-28 HIGH 7.1 CVE-2026-43672 An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26… macOS 14.8.8 / 15.7.8+ Fix from $1,9502026-07-27 HIGH 8.8 CVE-2026-42016 JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signa… Artifactory 7.133.11+ Fix from $1,9502026-07-27 HIGH 8.8 CVE-2026-17568 Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the … Devolutions Server 2026.1.24.0 / 2026.2.14.0+ Fix from $1,9502026-07-27 MEDIUM 6.3 CVE-2026-17529 A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The … No fix yet Fix from $1,6002026-07-27 MEDIUM 6.3 CVE-2026-17530 A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the… No fix yet Fix from $1,6002026-07-27 HIGH 8.0 CVE-2026-59689 An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF all… Connection Manager For Objectscale 7.2.54.19 / 7.2.63.3+ Fix from $1,9502026-07-27 HIGH 8.1 CVE-2026-8789 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce ver… No fix yet Fix from $1,9502026-07-24