Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Connect M6e 5g Firmware MEDIUM 5.4
CVE-2026-49192

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device d…

Mitigation only
Fix from $1,600 2026-06-04
Unclassified MEDIUM 5.3
CVE-2026-10597

OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific…

Mitigation only
Fix from $1,600 2026-06-04
T Mac Plus HIGH 8.8
CVE-2025-14772

Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Mitigation only
Fix from $1,950 2026-06-03
Sitefinity HIGH 8.8
CVE-2026-7201

CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, an…

Fix: 15.2.8441 / 15.3.8531+
Fix from $1,950 2026-06-02
Kiteworks MEDIUM 6.5
CVE-2026-24753

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data …

Fix: 9.3.0+
Fix from $1,600 2026-06-01
Kiteworks MEDIUM 5.4
CVE-2026-24755

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data …

Fix: 9.3.0+
Fix from $1,600 2026-06-01
Nextcloud Server MEDIUM 6.8
CVE-2026-45810

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, …

Fix: 21.0.9.20 / 22.2.10.35+
Fix from $1,600 2026-06-01
Nextcloud Server HIGH 8.1
CVE-2026-45281

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, w…

Fix: 21.0.9.23 / 22.2.10.39+
Fix from $1,950 2026-06-01
Kiteworks MEDIUM 6.5
CVE-2026-23638

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data …

Fix: 9.3.0+
Fix from $1,600 2026-06-01
Airflow HIGH 7.5
CVE-2026-41084

A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization a…

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10212

A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. …

Mitigation only
Fix from $1,600 2026-06-01
Unclassified HIGH 8.7
CVE-2026-47266

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a kno…

Mitigation only
Fix from $1,950 2026-05-29
Youtrack MEDIUM 6.5
CVE-2026-49386

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

Fix: 2026.1.13570+
Fix from $1,600 2026-05-29
Unclassified MEDIUM 5.3
CVE-2026-43917

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware only verifies the user is aut…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified MEDIUM 5.1
CVE-2026-45551

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authen…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified MEDIUM 6.5
CVE-2026-9493

Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attacke…

Mitigation only
Fix from $1,600 2026-05-29
Unclassified HIGH 7.1
CVE-2026-45342

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains an Insecure Direct Object Reference vulnerability in the …

Mitigation only
Fix from $1,950 2026-05-28
Keystone HIGH 8.8
CVE-2026-42999

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON re…

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-28
Unclassified MEDIUM 5.3
CVE-2026-45297

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 6.5
CVE-2026-41141

EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:id/prepare endpoint accepts a…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.3
CVE-2026-7651

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Buil…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 6.5
CVE-2026-3173

The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due …

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.3
CVE-2026-46544

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-suppl…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 8.8
CVE-2026-46414

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control …

Mitigation only
Fix from $1,950 2026-05-27
GitLab HIGH 8.2
CVE-2026-4868

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under…

Fix: 18.10.7 / 18.11.4+
Fix from $1,950 2026-05-27
Unclassified HIGH 8.8
CVE-2026-38807

Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserController.java component

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-42736

Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows Exploiting Incorrectly Config…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified MEDIUM 6.5
CVE-2026-42725

Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce all…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 8.2
CVE-2026-8890

code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by su…

Patch available
Fix from $1,950 2026-05-26
Unclassified MEDIUM 5.9
CVE-2026-44776

Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do not enforce library-level auth…

Mitigation only
Fix from $1,600 2026-05-26