Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 7.3
CVE-2026-71417

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using …

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-71308

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements ide…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-55166

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-si…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-69160

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use st…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-50167

Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpoints for listing and retrievi…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.8
CVE-2026-61574

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpo…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.3
CVE-2026-49225

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revis…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-49228

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product opera…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.6
CVE-2026-19869

@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-le…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.6
CVE-2026-49222

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product quest…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.6
CVE-2026-49223

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revie…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.3
CVE-2026-49224

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post revision…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-49221

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.3
CVE-2026-49226

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post operatio…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.6
CVE-2026-49227

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment opera…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-45120

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users w…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-74009

Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-73395

Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-73189

Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions.

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.6
CVE-2026-69189

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, c…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-16309

Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-63178

Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/u…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 8.8
CVE-2026-75103

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75105

phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/ind…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-63669

ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destinati…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 8.8
CVE-2026-74877

openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clien…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-19994

A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-14832

The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup e…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 8.3
CVE-2026-19979

A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, M…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-19966

A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/…

Fix unknown
Fix from $4,000 2026-08-17