Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified MEDIUM 6.5
CVE-2026-43934

e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized …

Patch available
Fix from $1,600 2026-05-26
Unclassified MEDIUM 5.3
CVE-2026-40127

OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated use…

Mitigation only
Fix from $1,600 2026-05-25
Azure Privileged Identity Management HIGH 8.8
CVE-2026-35430

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges ov…

Mitigation only
Fix from $1,950 2026-05-22
Unclassified HIGH 7.1
CVE-2026-39968

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution …

Patch available
Fix from $1,950 2026-05-22
Unclassified MEDIUM 6.5
CVE-2026-28444

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId …

Patch available
Fix from $1,600 2026-05-22
Mattermost Server HIGH 7.1
CVE-2026-3473

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, whi…

Fix: 10.11.15 / 11.4.5+
Fix from $1,950 2026-05-22
Unclassified HIGH 7.5
CVE-2026-8679

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the h…

Patch available
Fix from $1,950 2026-05-22
Concrete Cms MEDIUM 5.3
CVE-2026-8337

Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public an…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-8204

Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosu…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Litellm HIGH 8.8
CVE-2026-47101

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generat…

Fix: 1.83.14+
Fix from $1,950 2026-05-21
Unclassified HIGH 7.5
CVE-2025-13479

Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Truste…

Mitigation only
Fix from $1,950 2026-05-21
Unclassified HIGH 8.1
CVE-2026-45760

(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K…

Mitigation only
Fix from $1,950 2026-05-21
Unclassified CRITICAL 10.0
CVE-2026-9152

A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiri…

Mitigation only
Fix from $2,300 2026-05-21
Misp MEDIUM 6.5
CVE-2026-9136

A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request dat…

Fix: 2.5.38+
Fix from $1,600 2026-05-20
Build Of Keycloak HIGH 8.1
CVE-2026-9087

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identit…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified MEDIUM 6.5
CVE-2026-6072

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all vers…

Mitigation only
Fix from $1,600 2026-05-20
Pro Cloud Server HIGH 8.8
CVE-2026-42097

Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only …

Fix: after 6.1.167
Fix from $1,950 2026-05-19
Build Of Keycloak MEDIUM 6.8
CVE-2026-4630

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Ser…

Fix: 26.4.12+
Fix from $1,600 2026-05-19
Unclassified MEDIUM 6.9
CVE-2026-46721

The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignm…

Mitigation only
Fix from $1,600 2026-05-19
Unclassified MEDIUM 5.3
CVE-2026-33052

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add…

Patch available
Fix from $1,600 2026-05-19
Dify HIGH 7.5
CVE-2026-41949

Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up …

Fix: after 1.14.1
Fix from $1,950 2026-05-18
Dify CRITICAL 9.1
CVE-2026-41947EPSS 6%

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configuratio…

Fix: after 1.14.1
Fix from $2,300 2026-05-18
Weknora MEDIUM 6.3
CVE-2026-8786

A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file i…

Fix: after 0.3.6
Fix from $1,600 2026-05-18
Open Webui MEDIUM 6.5
CVE-2026-45666

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the API /api/v1/notes/{note_id} e…

Fix: 0.8.11+
Fix from $1,600 2026-05-15
Open Webui HIGH 8.3
CVE-2026-44570

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, authorization controls surroundin…

Fix: 0.6.19+
Fix from $1,950 2026-05-15
Open Webui HIGH 8.1
CVE-2026-45402

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multiple endpoints accept a user-s…

Fix: 0.9.5+
Fix from $1,950 2026-05-15
Open Webui HIGH 7.5
CVE-2026-45398

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() chec…

Fix: 0.9.5+
Fix from $1,950 2026-05-15
Open Webui HIGH 8.0
CVE-2026-45671

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permane…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 7.1
CVE-2026-45349

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a user just needs to use the API e…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Unclassified HIGH 8.1
CVE-2026-46407

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-toke…

Mitigation only
Fix from $1,950 2026-05-15