Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 8.8
CVE-2026-61460

Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, Quot…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 8.8
CVE-2026-6212

Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse. This issue aff…

Mitigation only
Fix from $1,950 2026-07-10
Snipe It MEDIUM 5.4
CVE-2026-55478

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but do…

Fix: 8.6.2+
Fix from $1,600 2026-07-10
Snipe It HIGH 7.7
CVE-2026-55516

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current ma…

Fix: 8.6.2+
Fix from $1,950 2026-07-10
Unclassified HIGH 8.7
CVE-2026-59190

grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.52 and earlier, an authenticat…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 8.8
CVE-2026-2398

Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue a…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-56765

Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling p…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 7.1
CVE-2026-41878

R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The application fetches files from th…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-6802

The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.6
CVE-2026-55604

DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 8.1
CVE-2026-51923

An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 8.1
CVE-2026-51924

An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 8.1
CVE-2026-51925

A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the df…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-59817

Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to…

Patch available
Fix from $1,600 2026-07-09
Open Webui CRITICAL 9.0
CVE-2026-59216

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and ex…

Fix: 0.10.0+
Fix from $2,300 2026-07-09
Unclassified MEDIUM 6.3
CVE-2026-15191

A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Re…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.5
CVE-2026-1989

Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allows Exploitation of Trusted Id…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-12418

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecur…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-13450

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Insecure Direct…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 8.8
CVE-2026-5523

The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.9
CVE-2026-54590

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio frame…

Patch available
Fix from $1,600 2026-07-08
Opencti HIGH 7.1
CVE-2026-35210

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vul…

Fix: 7.260326.0+
Fix from $1,950 2026-07-08
Server HIGH 8.0
CVE-2026-60104

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allo…

Fix: 2026.6.0+
Fix from $1,950 2026-07-08
N8n MEDIUM 5.0
CVE-2026-59253

n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folders in other projects. Att…

Fix: 2.28.0+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.3
CVE-2026-5459

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecur…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified HIGH 8.1
CVE-2026-3688

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in a…

Mitigation only
Fix from $1,950 2026-07-08
Coder HIGH 8.7
CVE-2026-55429

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertW…

Fix: 2.29.17 / 2.32.7+
Fix from $1,950 2026-07-08
Unclassified HIGH 7.1
CVE-2026-54602

FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates the caller but loads LLM reque…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 8.6
CVE-2026-55418

FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unrelated resource and then sign…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 7.1
CVE-2026-50530

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matc…

Patch available
Fix from $1,950 2026-07-07