Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 7.1
CVE-2026-42516

This vulnerability exists in e-Sushrut due to improper authorization checks during resource access. An authenticated attacker could exploit this vuln…

Mitigation only
Fix from $1,950 2026-04-29
Unclassified HIGH 7.1
CVE-2026-42517

This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could ex…

Mitigation only
Fix from $1,950 2026-04-29
Outline HIGH 7.7
CVE-2026-41649

Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.…

Fix: 1.7.0+
Fix from $1,950 2026-04-28
Openclaw MEDIUM 5.4
CVE-2026-41406

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can …

Fix: 2026.3.31+
Fix from $1,600 2026-04-28
Nvflare CRITICAL 9.8
CVE-2026-24178

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause author…

Fix: 2.7.2+
Fix from $2,300 2026-04-28
Openclaw MEDIUM 5.8
CVE-2026-41372

OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. …

Fix: 2026.4.2+
Fix from $1,600 2026-04-28
Unclassified HIGH 7.1
CVE-2026-28747

A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.

Mitigation only
Fix from $1,950 2026-04-27
Unclassified MEDIUM 5.4
CVE-2026-7145

A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/Workspa…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 5.3
CVE-2025-15626

Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application

No fix yet
Fix from $1,600 2026-04-27
Unclassified MEDIUM 5.3
CVE-2026-6810

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63…

Mitigation only
Fix from $1,600 2026-04-24
Unclassified MEDIUM 5.3
CVE-2026-2028

The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi…

Patch available
Fix from $1,600 2026-04-24
Unclassified HIGH 8.7
CVE-2026-6375

A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PN…

Mitigation only
Fix from $1,950 2026-04-23
Flowise HIGH 8.8
CVE-2026-41277

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the Docum…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 7.5
CVE-2026-41279

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41267

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Thinkphp CRITICAL 9.8
CVE-2018-25270

ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functi…

Fix: 5.0.23+
Fix from $2,300 2026-04-22
Unclassified HIGH 7.6
CVE-2026-5750

An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated users to access data belonging …

Mitigation only
Fix from $1,950 2026-04-22
Augmentt MEDIUM 6.5
CVE-2026-6355

A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insec…

Fix: 2025-10-02+
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.5
CVE-2026-41127

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite capt…

Mitigation only
Fix from $1,600 2026-04-22
Enterprise Server CRITICAL 9.6
CVE-2026-5845

An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attac…

Fix: 3.14.26 / 3.15.21+
Fix from $2,300 2026-04-21
Avideo MEDIUM 6.5
CVE-2026-40907

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an In…

Fix: after 29.0
Fix from $1,600 2026-04-21
Unclassified HIGH 7.1
CVE-2026-40865

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document vie…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified HIGH 8.6
CVE-2026-40866

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upl…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified HIGH 7.1
CVE-2026-40867

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment…

Mitigation only
Fix from $1,950 2026-04-21
Crafty Controller CRITICAL 9.0
CVE-2026-5652

An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform …

Fix: 4.10.4+
Fix from $2,300 2026-04-21
Unclassified HIGH 7.6
CVE-2026-40589

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an…

Patch available
Fix from $1,950 2026-04-21
Unclassified HIGH 7.1
CVE-2026-40591

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-control…

Patch available
Fix from $1,950 2026-04-21
Unclassified MEDIUM 5.7
CVE-2026-40570

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` …

Patch available
Fix from $1,600 2026-04-21
Neko HIGH 8.8
CVE-2026-39386

Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticat…

Fix: 3.0.11 / 3.1.2+
Fix from $1,950 2026-04-21
Unclassified MEDIUM 6.5
CVE-2025-66954

A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid usernames an…

Mitigation only
Fix from $1,600 2026-04-20