Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified MEDIUM 5.3
CVE-2026-12998

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-13358

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference…

No fix yet
Fix from $4,000 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-16142

The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_…

No fix yet
Fix from $5,750 2026-08-15
Unclassified MEDIUM 5.3
CVE-2026-74242

A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (U…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.6
CVE-2026-19870

Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-73841

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go an…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-73039

streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete othe…

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.9
CVE-2026-73656

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/ba…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72680

Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.8
CVE-2026-72666

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigne…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72657

Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variab…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.1
CVE-2026-72629

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Prop…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-73644

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.1
CVE-2026-72741

Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauth…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.9
CVE-2026-58432

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-58435

Gitea LFS Deploy-Key Privilege Escalation

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.9
CVE-2026-57886

Cross-repository issue/comment attachment re-linking can expose private attachment content

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.6
CVE-2026-19734

Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-28155

Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-73616

OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to ot…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-73606

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-prote…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-73610

SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the administrator's entire storage map…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.1
CVE-2026-73612

File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authentica…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.0
CVE-2026-73488

Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpo…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.2
CVE-2026-18945

The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling …

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-18750

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the …

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-18744

Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func on…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-18749

The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefac…

No fix yet
Fix from $5,750 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-19130

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub clust…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.2
CVE-2026-73303

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId with…

No fix yet
Fix from $4,900 2026-08-12