Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified MEDIUM 5.3
CVE-2026-11896

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.3
CVE-2026-12657

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.3
CVE-2026-5348

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in vers…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.3
CVE-2026-50283

Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain an authorization issue in th…

Patch available
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.9
CVE-2026-49858

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missin…

Mitigation only
Fix from $1,600 2026-07-01
Satellite MEDIUM 6.5
CVE-2026-5135

A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing…

Fix: 3.18.2 / 3.19.1+
Fix from $1,600 2026-07-01
Satellite MEDIUM 6.5
CVE-2026-5142

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (…

Fix: 3.18.2 / 3.19.1+
Fix from $1,600 2026-07-01
Mycomplianceoffice HIGH 8.1
CVE-2026-53903

MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-11988

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in al…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 8.8
CVE-2026-56230

Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the client-controlled x-limited-key-…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified MEDIUM 6.5
CVE-2026-58447

Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attacke…

Patch available
Fix from $1,600 2026-06-30
Langflow CRITICAL 9.6
CVE-2026-10140

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. A…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Unclassified MEDIUM 5.0
CVE-2026-27881

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/deployments…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified MEDIUM 5.0
CVE-2026-27883

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deploym…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-12073

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versio…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified HIGH 7.7
CVE-2026-34592

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, Coolify server and proje…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified CRITICAL 9.6
CVE-2026-57498

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controller…

Mitigation only
Fix from $2,300 2026-06-29
Unclassified MEDIUM 6.4
CVE-2026-57956

SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by su…

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 5.9
CVE-2026-57943

LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users t…

Patch available
Fix from $1,600 2026-06-29
Unclassified HIGH 7.5
CVE-2026-56780

Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domai…

Patch available
Fix from $1,950 2026-06-29
Unclassified MEDIUM 5.3
CVE-2026-56781

Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data…

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-57341

Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.

Mitigation only
Fix from $1,600 2026-06-29
Unclassified MEDIUM 5.4
CVE-2026-13549

A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file appli…

Mitigation only
Fix from $1,600 2026-06-29
Unclassified MEDIUM 5.0
CVE-2026-13534

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryServi…

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.3
CVE-2026-13512

A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/ser…

Patch available
Fix from $1,600 2026-06-28
Unclassified MEDIUM 5.4
CVE-2026-52779

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-52782

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/projec…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-44736

OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user …

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.4
CVE-2026-56823

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/…

Mitigation only
Fix from $1,600 2026-06-26
Lxd CRITICAL 9.6
CVE-2026-12411

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gu…

Fix: 6.9+
Fix from $2,300 2026-06-26