Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 7.1
CVE-2026-8406

openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the mes…

Patch available
Fix from $1,950 2026-06-11
GitLab HIGH 8.7
CVE-2026-6552

GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under …

Fix: 18.10.8 / 18.11.5+
Fix from $1,950 2026-06-11
Unclassified MEDIUM 6.3
CVE-2026-53911

Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operations and certain custom en…

Patch available
Fix from $1,600 2026-06-11
Unclassified MEDIUM 5.3
CVE-2023-40200

Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting …

Mitigation only
Fix from $1,600 2026-06-11
Unclassified HIGH 7.7
CVE-2026-44692

Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that autho…

Mitigation only
Fix from $1,950 2026-06-10
Plane HIGH 8.3
CVE-2026-46558

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated…

Fix: 1.3.1+
Fix from $1,950 2026-06-10
Migration Assessment HIGH 8.1
CVE-2026-53470

A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/…

Fix: 0.13.5+
Fix from $1,950 2026-06-10
Migration Assessment HIGH 7.7
CVE-2026-53471

A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory an…

Fix: 0.13.5+
Fix from $1,950 2026-06-10
Unclassified CRITICAL 9.1
CVE-2026-45550

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smo…

Mitigation only
Fix from $2,300 2026-06-10
Unclassified CRITICAL 9.9
CVE-2026-45552

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares …

Mitigation only
Fix from $2,300 2026-06-10
Unclassified HIGH 8.1
CVE-2026-53673

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access a…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 8.6
CVE-2026-6444

A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functio…

Mitigation only
Fix from $1,950 2026-06-09
Qumagie CRITICAL 9.8
CVE-2026-44083

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vuln…

Fix: 2.9.0+
Fix from $2,300 2026-06-09
Unclassified HIGH 7.5
CVE-2026-9185

The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.…

Mitigation only
Fix from $1,950 2026-06-09
Unclassified HIGH 7.1
CVE-2026-49141

WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access an…

Patch available
Fix from $1,950 2026-06-08
Flowise CRITICAL 9.6
CVE-2026-46441

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $2,300 2026-06-08
Flowise CRITICAL 9.6
CVE-2026-42861

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $2,300 2026-06-08
Flowise MEDIUM 5.0
CVE-2026-42862

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $1,600 2026-06-08
Flowise HIGH 8.1
CVE-2026-42863

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Unclassified MEDIUM 5.0
CVE-2026-11500

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authenticat…

Patch available
Fix from $1,600 2026-06-08
Unclassified MEDIUM 6.3
CVE-2026-11461

A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state…

Mitigation only
Fix from $1,600 2026-06-07
Unclassified HIGH 7.2
CVE-2026-9851

The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is…

Mitigation only
Fix from $1,950 2026-06-06
Unclassified MEDIUM 5.3
CVE-2026-8839

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and inc…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified MEDIUM 5.3
CVE-2026-7665EPSS 7%

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified MEDIUM 6.9
CVE-2026-46390

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0.0, the gitlist plugin is exp…

Mitigation only
Fix from $1,600 2026-06-05
Termix CRITICAL 9.0
CVE-2026-45750

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fi…

Fix: 2.3.2+
Fix from $2,300 2026-06-05
Termix CRITICAL 9.0
CVE-2026-45746

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manage…

Fix: 2.3.2+
Fix from $2,300 2026-06-05
Termix HIGH 8.1
CVE-2026-45743

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-manager endpoints in Termix pri…

Fix: 2.3.2+
Fix from $1,950 2026-06-05
Unclassified HIGH 7.1
CVE-2026-11369

The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization checks to verify that the request…

Mitigation only
Fix from $1,950 2026-06-05
Chrome MEDIUM 6.5
CVE-2026-11142

Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04