Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 7.6
CVE-2026-46408

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accep…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified MEDIUM 5.3
CVE-2026-44718

Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, e…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified HIGH 7.1
CVE-2026-44678

Tuist is a virtual platform team for Swift app devs. In 1.180.8 and earlier, the DELETE /api/projects/{account_handle}/{project_handle}/previews/{pre…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 8.1
CVE-2026-8629

Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, a…

Patch available
Fix from $1,950 2026-05-14
Hatchet MEDIUM 6.5
CVE-2026-42572

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a missing authorization direct…

Fix: 0.83.39+
Fix from $1,600 2026-05-14
Unclassified HIGH 8.6
CVE-2026-44504

Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a …

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 8.8
CVE-2025-15025

Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry …

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 7.1
CVE-2026-5798

Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation …

Mitigation only
Fix from $1,950 2026-05-14
Unclassified MEDIUM 6.8
CVE-2026-6008

Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Edu…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified HIGH 8.8
CVE-2025-12008

Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Funct…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified CRITICAL 9.8
CVE-2026-2347

Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hi…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified MEDIUM 5.3
CVE-2026-6206

The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from…

Patch available
Fix from $1,600 2026-05-14
Unclassified HIGH 8.2
CVE-2026-5395

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 8.2
CVE-2026-5396

The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21.…

Mitigation only
Fix from $1,950 2026-05-14
Shellhub MEDIUM 6.5
CVE-2026-44423

ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any authenticated caller, without …

Fix: 0.24.2+
Fix from $1,600 2026-05-13
Shellhub MEDIUM 6.5
CVE-2026-44424

ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever the caller is authenticated, wi…

Fix: 0.24.2+
Fix from $1,600 2026-05-13
Shellhub MEDIUM 6.5
CVE-2026-44426

ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object — including the members list (u…

Fix: 0.24.2+
Fix from $1,600 2026-05-13
Sqlbot HIGH 8.1
CVE-2026-42463

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure …

Fix: 1.8.0+
Fix from $1,950 2026-05-13
Unclassified MEDIUM 5.3
CVE-2026-6965

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and inc…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified MEDIUM 5.3
CVE-2025-14033

The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified MEDIUM 5.3
CVE-2026-44341

GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job detai…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-42889

Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebS…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-29204

Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without a…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified MEDIUM 5.4
CVE-2023-30059

An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the ch…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 8.8
CVE-2026-6001

Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This i…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 7.7
CVE-2026-43890

Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API endpoint in server/routes/api/su…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 8.1
CVE-2026-38568

HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /inte…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 7.7
CVE-2026-33356

In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and rece…

Mitigation only
Fix from $1,950 2026-05-11
Grav HIGH 8.1
CVE-2026-42609

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with o…

Fix: after 1.8.0
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.8
CVE-2026-42291

SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoints for reading and creating s…

Mitigation only
Fix from $1,600 2026-05-08