Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.3 CVE-2026-64651 The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.28, the tool relay authorizes … No fix yet Fix from $1,6002026-07-20 MEDIUM 6.3 CVE-2026-44509 Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, previous bug fix… No fix yet Fix from $1,6002026-07-20 CRITICAL 9.1 CVE-2026-44231 RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an informa… Request Tracker 5.0.10 / 6.0.3+ Fix from $2,3002026-07-20 MEDIUM 6.5 CVE-2026-63755 SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON D… Surrealdb 3.1.0+ Fix from $1,6002026-07-20 MEDIUM 6.5 CVE-2026-63740 SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elemen… Surrealdb 3.1.4+ Fix from $1,6002026-07-20 MEDIUM 6.5 CVE-2026-63733 SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with en… Surrealdb 3.2.0+ Fix from $1,6002026-07-20 MEDIUM 6.5 CVE-2026-16215 A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Ha… No fix yet Fix from $1,6002026-07-19 HIGH 7.3 CVE-2026-16200 A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of t… No fix yet Fix from $1,9502026-07-19 MEDIUM 6.3 CVE-2026-16197 A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/… No fix yet Fix from $1,6002026-07-18 HIGH 8.2 CVE-2026-10130 QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing account… No fix yet Fix from $1,9502026-07-18 MEDIUM 6.3 CVE-2026-16195 A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/w… No fix yet Fix from $1,6002026-07-18 HIGH 7.3 CVE-2026-16126 A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm… No fix yet Fix from $1,9502026-07-18 MEDIUM 6.3 CVE-2026-16123 A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the fi… No fix yet Fix from $1,6002026-07-18 MEDIUM 6.3 CVE-2026-16119 A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval… No fix yet Fix from $1,6002026-07-18 HIGH 8.8 CVE-2025-71390 SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access r… Surrealdb 2.1.8 / 2.2.6+ Fix from $1,9502026-07-18 HIGH 8.3 CVE-2026-47866 VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Cont… No fix yet Fix from $1,9502026-07-18 CRITICAL 9.6 CVE-2026-55518 Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_… No fix yet Fix from $2,3002026-07-17 MEDIUM 6.5 CVE-2026-4938 IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 thr… Security Verify Access after 11.0.2.0 Fix from $1,6002026-07-17 HIGH 7.1 CVE-2026-14871 osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJ… No fix yet Fix from $1,9502026-07-17 MEDIUM 6.3 CVE-2026-16017 A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the compo… No fix yet Fix from $1,6002026-07-17 HIGH 8.8 CVE-2026-62228 OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyo… Openclaw 2026.6.5+ Fix from $1,9502026-07-17 HIGH 8.1 CVE-2026-62231 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, … Mitigation only Fix from $1,9502026-07-17 MEDIUM 5.4 CVE-2026-62221 OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature i… Openclaw 2026.5.26+ Fix from $1,6002026-07-17 HIGH 8.8 CVE-2026-62223 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execut… Openclaw 2026.5.18+ Fix from $1,9502026-07-17 MEDIUM 5.4 CVE-2026-62224 OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attacker… No fix yet Fix from $1,6002026-07-17 MEDIUM 5.4 CVE-2026-62225 OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute… Openclaw 2026.5.18+ Fix from $1,6002026-07-17 HIGH 8.8 CVE-2026-62217 OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachab… Openclaw 2026.5.27+ Fix from $1,9502026-07-17 HIGH 7.1 CVE-2026-62219 OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or co… Openclaw 2026.5.26+ Fix from $1,9502026-07-17 HIGH 8.1 CVE-2026-62209 OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore … Openclaw 2026.6.5+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-62202 OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to rega… Openclaw 2026.6.9+ Fix from $1,9502026-07-17