Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Openproject HIGH 7.1
CVE-2026-40896

OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas` permission in any project ca…

Fix: 17.3.0+
Fix from $1,950 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6613

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_schedule/get_schedule_data of …

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6614

A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_pr…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6612

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_execution/update_agent_execution of t…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 5.4
CVE-2026-6584

A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_user of the file superagi/contr…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 5.4
CVE-2026-6585

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6586

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/co…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 5.4
CVE-2026-6583

A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14. This affects the function delete_api_key/edit_api_key of the file superag…

Mitigation only
Fix from $1,600 2026-04-19
Unclassified MEDIUM 6.3
CVE-2026-6571

A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/co…

Mitigation only
Fix from $1,600 2026-04-19
Unclassified HIGH 7.1
CVE-2026-40480

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person re…

Patch available
Fix from $1,950 2026-04-18
Unclassified MEDIUM 5.3
CVE-2026-5234

The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability e…

Mitigation only
Fix from $1,600 2026-04-17
Vault HIGH 8.1
CVE-2026-3605

An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or…

Fix: 1.19.16 / 1.20.10+
Fix from $1,950 2026-04-17
Unclassified HIGH 8.8
CVE-2026-40308

My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJAX endpoint, registered for un…

Mitigation only
Fix from $1,950 2026-04-16
Unclassified MEDIUM 5.3
CVE-2026-4160

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje…

Mitigation only
Fix from $1,600 2026-04-16
Unclassified HIGH 8.1
CVE-2026-40784

Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Config…

Mitigation only
Fix from $1,950 2026-04-15
Unclassified MEDIUM 5.3
CVE-2026-40737

Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exploiting Incorrectly Configure…

No fix yet
Fix from $1,600 2026-04-15
Unclassified HIGH 8.8
CVE-2026-5617

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_r…

Mitigation only
Fix from $1,950 2026-04-15
Docmost MEDIUM 5.4
CVE-2026-34213

Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.71.0, improper authorization i…

Fix: 0.71.0+
Fix from $1,600 2026-04-14
Chamilo Lms MEDIUM 6.5
CVE-2026-34370

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Ref…

Fix: after 1.11.38
Fix from $1,600 2026-04-14
Chamilo Lms HIGH 7.1
CVE-2026-34602

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecu…

Fix: after 1.11.38
Fix from $1,950 2026-04-14
Krayin Crm HIGH 8.8
CVE-2026-38529

A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to…

No fix yet
Fix from $1,950 2026-04-14
Krayin Crm HIGH 8.1
CVE-2026-38530

A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated atta…

No fix yet
Fix from $1,950 2026-04-14
Krayin Crm HIGH 8.1
CVE-2026-38532

A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated att…

No fix yet
Fix from $1,950 2026-04-14
Mcphub MEDIUM 5.3
CVE-2025-13822

MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an un…

Fix: 0.11.0+
Fix from $1,600 2026-04-14
Unclassified HIGH 8.8
CVE-2026-25654

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when proces…

Mitigation only
Fix from $1,950 2026-04-14
Espocrm MEDIUM 5.4
CVE-2026-33740

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contai…

Fix: 9.3.4+
Fix from $1,600 2026-04-13
Unclassified MEDIUM 6.5
CVE-2026-40043

Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low-privilege users to escalate …

Mitigation only
Fix from $1,600 2026-04-13
Fastgpt HIGH 8.1
CVE-2026-40252

FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access…

Fix: 4.14.10.4+
Fix from $1,950 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-33736

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can enumerate all platform users an…

Patch available
Fix from $1,600 2026-04-10
Chamilo Lms HIGH 7.1
CVE-2026-33702

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Object Reference (IDOR) vulnera…

Fix: 1.11.38+
Fix from $1,950 2026-04-10