Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.8 CVE-2026-15704 In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by incon… No fix yet Fix from $2,3002026-07-24 CRITICAL 9.9 CVE-2026-15630 A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a… No fix yet Fix from $2,3002026-07-23 HIGH 7.1 CVE-2026-59678 An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the net… No fix yet Fix from $1,9502026-07-23 MEDIUM 6.3 CVE-2026-13067 When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configur… MongoDB 8.0.28 / 8.3.7+ Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-13060 An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an incons… MongoDB 7.0.39 / 8.0.28+ Fix from $1,6002026-07-22 HIGH 8.8 CVE-2026-65601 Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spe… Traefik 3.7.7+ Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-65602 Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTranspo… Traefik 3.6.23 / 3.7.7+ Fix from $1,9502026-07-22 MEDIUM 6.5 CVE-2026-65594 n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify … N8n 2.29.8+ Fix from $1,6002026-07-22 HIGH 8.1 CVE-2026-65596 n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic… N8n 1.123.64 / 2.29.8+ Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-65015 n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authoriza… N8n 2.29.8+ Fix from $1,9502026-07-22 MEDIUM 5.0 CVE-2026-63142 Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound … Kibana 8.19.19 / 9.3.8+ Fix from $1,6002026-07-21 HIGH 7.6 CVE-2026-61325 Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The supported version that is af… Advanced Benefits No fix yet Fix from $1,9502026-07-21 HIGH 7.1 CVE-2026-61012 Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected… Time And Labor after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.1 CVE-2026-60951 Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected… Time And Labor after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.4 CVE-2026-60723 Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are … Data Integrator No fix yet Fix from $1,9502026-07-21 CRITICAL 9.9 CVE-2026-60663 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a… Webcenter Content No fix yet Fix from $2,3002026-07-21 HIGH 7.8 CVE-2026-60625 Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). Supported versions that are affected are 12.2.1… Data Integrator No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-60320 Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affecte… Data Integrator No fix yet Fix from $1,9502026-07-21 HIGH 8.9 CVE-2026-43945 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to ach… Mitigation only Fix from $1,9502026-07-21 HIGH 7.7 CVE-2026-43946 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint … No fix yet Fix from $1,9502026-07-21 HIGH 8.9 CVE-2026-43947 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability wh… No fix yet Fix from $1,9502026-07-21 HIGH 7.1 CVE-2026-47697 Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). Prior to version 1.20.2, seve… No fix yet Fix from $1,9502026-07-21 MEDIUM 6.5 CVE-2026-56144 Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorizatio… Elasticsearch 8.19.18 / 9.3.7+ Fix from $1,6002026-07-21 MEDIUM 5.4 CVE-2026-56146 Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential informati… Kibana 9.4.3+ Fix from $1,6002026-07-21 CRITICAL 9.4 CVE-2026-47407 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources un… No fix yet Fix from $2,3002026-07-21 HIGH 8.6 CVE-2026-15829 A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of… No fix yet Fix from $1,9502026-07-21 CRITICAL 9.3 CVE-2026-65049 Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administr… Mitigation only Fix from $2,3002026-07-21 HIGH 8.8 CVE-2026-59851 A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos princ… Hardened Images No fix yet Fix from $1,9502026-07-21 MEDIUM 6.1 CVE-2026-47128 nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow acce… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.3 CVE-2026-64650 The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command line interface. Prior to vers… No fix yet Fix from $1,6002026-07-20