Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified MEDIUM 5.3
CVE-2026-54105

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic D…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified HIGH 7.1
CVE-2026-50141

Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any authen…

Patch available
Fix from $1,950 2026-06-18
Unclassified HIGH 7.1
CVE-2026-48759

TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability through cross-workspace Theme Tem…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.2
CVE-2026-50194

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management…

Patch available
Fix from $1,950 2026-06-17
Unclassified MEDIUM 6.5
CVE-2026-55197

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose …

Patch available
Fix from $1,600 2026-06-17
Unclassified MEDIUM 6.5
CVE-2026-55198

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access …

Patch available
Fix from $1,600 2026-06-17
Unclassified MEDIUM 5.3
CVE-2025-15657

Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.

Mitigation only
Fix from $1,600 2026-06-17
Unclassified HIGH 8.2
CVE-2026-54184

Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 7.3
CVE-2026-40768

Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.

Mitigation only
Fix from $1,950 2026-06-17
Openclaw MEDIUM 6.5
CVE-2026-53863

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who ca…

Fix: 2026.4.25+
Fix from $1,600 2026-06-16
Unclassified HIGH 7.6
CVE-2026-48599

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belon…

Patch available
Fix from $1,950 2026-06-15
Unclassified HIGH 7.5
CVE-2026-52699

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.5
CVE-2026-48868

Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.5
CVE-2026-48872

Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 6.3
CVE-2026-40792

Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified HIGH 7.1
CVE-2026-39518

Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.5
CVE-2025-59133

Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.3
CVE-2026-12204

A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveInteg…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 8.8
CVE-2026-54361

MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Se…

Patch available
Fix from $1,950 2026-06-12
Unclassified MEDIUM 5.1
CVE-2026-54357

An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to si…

Patch available
Fix from $1,600 2026-06-12
Unclassified HIGH 8.4
CVE-2026-54360

A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a …

Patch available
Fix from $1,950 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-53726

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a…

Patch available
Fix from $1,600 2026-06-12
Unclassified HIGH 8.8
CVE-2026-42947

A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbi…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified HIGH 8.8
CVE-2026-8828

A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, …

Mitigation only
Fix from $1,950 2026-06-12
Chromadb HIGH 8.8
CVE-2026-45830

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, writ…

Fix: after 1.5.9
Fix from $1,950 2026-06-12
Chromadb HIGH 8.8
CVE-2026-45832

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers t…

Fix: after 1.5.9
Fix from $1,950 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-44207

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access …

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.5
CVE-2026-47238

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subt…

Mitigation only
Fix from $1,600 2026-06-11
Unclassified HIGH 8.3
CVE-2026-47189

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the AutoMod remove flow looks up a…

Mitigation only
Fix from $1,950 2026-06-11
Langflow HIGH 8.1
CVE-2026-7787

IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using inse…

Fix: 1.9.2+
Fix from $1,950 2026-06-11