Vulnerability index

Browse CVEs

2,820 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2026-43977 wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout ses… No fix yet Fix from $1,9502026-07-16 HIGH 7.3 CVE-2026-62290 cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing an… Cert Manager 1.19.6 / 1.20.3+ Fix from $1,9502026-07-16 MEDIUM 5.4 CVE-2026-47082 An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacat… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.5 CVE-2026-47084 An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user… No fix yet Fix from $1,6002026-07-16 HIGH 8.8 CVE-2026-63085 Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate… No fix yet Fix from $1,9502026-07-16 MEDIUM 5.4 CVE-2026-55608 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP… N8n Mcp 2.57.4+ Fix from $1,6002026-07-15 MEDIUM 5.4 CVE-2026-56743 Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-base… Cilium 1.19.5+ Fix from $1,6002026-07-15 HIGH 8.3 CVE-2026-59258 immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to m… Mitigation only Fix from $1,9502026-07-15 MEDIUM 5.9 CVE-2026-61643 FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that po… Mitigation only Fix from $1,6002026-07-15 CRITICAL 9.1 CVE-2026-53512 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth toke… Better Auth 1.6.11+ Fix from $2,3002026-07-15 HIGH 7.1 CVE-2026-53515 Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register… Better Auth\/sso 1.6.11+ Fix from $1,9502026-07-15 MEDIUM 5.4 CVE-2026-49997 SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::purge_edges in surrealdb… Mitigation only Fix from $1,6002026-07-15 HIGH 8.8 CVE-2026-55242 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational… Mitigation only Fix from $1,9502026-07-15 HIGH 7.7 CVE-2026-61644 FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint aut… Mitigation only Fix from $1,9502026-07-15 HIGH 7.1 CVE-2026-54563 Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send pat… Mitigation only Fix from $1,9502026-07-15 HIGH 7.6 CVE-2026-54560 Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth… Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.1 CVE-2026-60087 PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arb… Mitigation only Fix from $1,6002026-07-15 HIGH 7.3 CVE-2026-15752 A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the fil… Mitigation only Fix from $1,9502026-07-14 HIGH 8.2 CVE-2026-49981 Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template insta… Twig 3.27.0+ Fix from $1,9502026-07-14 CRITICAL 9.1 CVE-2026-48807 Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replac… Twig 3.27.0+ Fix from $2,3002026-07-14 HIGH 7.5 CVE-2026-48808 Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current… Twig 3.27.0+ Fix from $1,9502026-07-14 CRITICAL 9.1 CVE-2026-48806 Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP t… Twig 3.27.0+ Fix from $2,3002026-07-14 MEDIUM 6.5 CVE-2026-47732 Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without co… Twig 3.26.0+ Fix from $1,6002026-07-14 MEDIUM 5.3 CVE-2026-46635 Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic prop… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.5 CVE-2026-59889 jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5,… Mitigation only Fix from $1,6002026-07-14 CRITICAL 9.0 CVE-2026-48327 ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. … Coldfusion Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.3 CVE-2026-48321 ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnera… Coldfusion Mitigation only Fix from $2,3002026-07-14 HIGH 8.2 CVE-2026-50528 Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. .net 8.0.29 / 9.0.18+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-48489 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, Defaul… Symfony 5.4.53 / 6.4.41+ Fix from $1,9502026-07-14 HIGH 8.1 CVE-2026-48349 Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exp… Animate 23.0.16 / 24.0.14+ Fix from $1,9502026-07-14