Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 8.7
CVE-2026-53729

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (/exportCenter/download/{id}),…

Patch available
Fix from $1,950 2026-07-07
Airflow MEDIUM 6.5
CVE-2026-49296

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/…

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Unclassified HIGH 7.5
CVE-2026-5730

Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 7.5
CVE-2026-5799

Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 7.1
CVE-2026-57868

MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 7.1
CVE-2026-57869

Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access …

Mitigation only
Fix from $1,950 2026-07-07
Unclassified MEDIUM 5.3
CVE-2026-57870

Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified CRITICAL 9.9
CVE-2026-34037

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire a…

Patch available
Fix from $2,300 2026-07-07
Unclassified HIGH 7.7
CVE-2026-34044

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the Logs::mount() compon…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 8.7
CVE-2026-53643

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unaut…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 8.6
CVE-2026-53644

FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticated clients to both read and re…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified MEDIUM 5.0
CVE-2026-34167

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the ActivityMonitor Live…

Patch available
Fix from $1,600 2026-07-06
Unclassified HIGH 8.1
CVE-2026-59712

Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential…

Patch available
Fix from $1,950 2026-07-06
Unclassified CRITICAL 9.3
CVE-2026-12686

An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted …

Mitigation only
Fix from $2,300 2026-07-06
Camel MEDIUM 5.3
CVE-2026-48206

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component. The camel-jira producers r…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel MEDIUM 5.3
CVE-2026-49099

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key …

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel HIGH 7.5
CVE-2026-46585

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene produce…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel MEDIUM 5.3
CVE-2026-46453

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elast…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Unclassified HIGH 7.3
CVE-2026-14753

A vulnerability was detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This impacts an unknown function of the file /PHP…

Mitigation only
Fix from $1,950 2026-07-05
Unclassified HIGH 7.1
CVE-2026-28740

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lac…

Patch available
Fix from $1,950 2026-07-03
Unclassified MEDIUM 5.3
CVE-2026-25782

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion at…

Patch available
Fix from $1,600 2026-07-03
Unclassified HIGH 7.5
CVE-2026-27657

Gitea versions before 1.25.5 allow a user to change another user's primary email address.

Patch available
Fix from $1,950 2026-07-03
Build Of Keycloak MEDIUM 5.4
CVE-2026-14614

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue al…

Fix: 26.4.14 / 26.6.5+
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.9
CVE-2026-59234

Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventControl…

Patch available
Fix from $1,600 2026-07-03
Unclassified MEDIUM 5.3
CVE-2026-9180

The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and i…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.5
CVE-2026-59098

LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic search functionality that allows…

Patch available
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.0
CVE-2026-59100

LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other user…

Patch available
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.9
CVE-2026-58580

LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, upda…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57680

Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.3
CVE-2026-9188

The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ve…

Mitigation only
Fix from $1,600 2026-07-02