Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 8.8
CVE-2026-42205

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in th…

Mitigation only
Fix from $1,950 2026-05-08
Mailenable CRITICAL 9.8
CVE-2026-44400

MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers …

Fix: 10.56+
Fix from $2,300 2026-05-08
Solidtime MEDIUM 5.8
CVE-2026-42279

solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API accepts a…

Patch available
Fix from $1,600 2026-05-08
Onyx MEDIUM 6.5
CVE-2026-42277

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to…

Fix: 3.0.9 / 3.1.6+
Fix from $1,600 2026-05-08
Unclassified HIGH 8.8
CVE-2026-42278

UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a crit…

Patch available
Fix from $1,950 2026-05-08
Unclassified HIGH 7.1
CVE-2026-41906

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hide…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified MEDIUM 5.3
CVE-2026-27329

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Cont…

No fix yet
Fix from $1,600 2026-05-07
Spring Cloud Config HIGH 7.5
CVE-2026-40981

When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially expos…

Fix: 3.1.14 / 4.1.10+
Fix from $1,950 2026-05-07
Unclassified MEDIUM 5.4
CVE-2026-20219

A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of other users …

Mitigation only
Fix from $1,600 2026-05-06
Velociraptor HIGH 7.7
CVE-2026-7573

An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-p…

Fix: 0.76.5+
Fix from $1,950 2026-05-06
Dify MEDIUM 6.5
CVE-2026-41950

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded…

Fix: 1.14.0+
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.5
CVE-2026-3454

The GenerateBlocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.0. This is due to…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified MEDIUM 5.3
CVE-2026-2729

The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.3
CVE-2026-7782

A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Cli…

Mitigation only
Fix from $1,600 2026-05-04
N8n MEDIUM 6.5
CVE-2026-42227

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped…

Fix: 1.123.32 / 2.17.4+
Fix from $1,600 2026-05-04
Unclassified HIGH 7.5
CVE-2026-41471

The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerability in the QR code scanning end…

Mitigation only
Fix from $1,950 2026-05-04
Unclassified CRITICAL 9.9
CVE-2026-29200

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows …

Mitigation only
Fix from $2,300 2026-05-04
Unclassified MEDIUM 5.3
CVE-2026-7702

A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the file /workspace/:workspaceId…

No fix yet
Fix from $1,600 2026-05-03
Unclassified MEDIUM 6.5
CVE-2026-5337

During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Obj…

Mitigation only
Fix from $1,600 2026-05-03
Unclassified MEDIUM 6.5
CVE-2026-7681

A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an unknown functionality of the …

Mitigation only
Fix from $1,600 2026-05-03
Unclassified HIGH 8.1
CVE-2026-2554

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direc…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 8.1
CVE-2026-7491

School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific p…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified MEDIUM 5.3
CVE-2026-7638

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 6.3
CVE-2026-7510

A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark…

Patch available
Fix from $1,600 2026-04-30
Langflow HIGH 8.1
CVE-2026-6542

IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users…

Fix: 1.9.0+
Fix from $1,950 2026-04-30
Unclassified MEDIUM 5.4
CVE-2026-7502

A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/…

Patch available
Fix from $1,600 2026-04-30
Langflow Desktop HIGH 7.5
CVE-2026-4503

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference…

Fix: after 1.8.4
Fix from $1,950 2026-04-30
Unclassified HIGH 8.1
CVE-2026-40600

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Char…

Mitigation only
Fix from $1,950 2026-04-30
Unclassified HIGH 8.1
CVE-2026-7399

Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects P…

Mitigation only
Fix from $1,950 2026-04-30
Unclassified HIGH 7.1
CVE-2026-42515

This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vul…

Mitigation only
Fix from $1,950 2026-04-29