Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Chamilo Lms MEDIUM 6.5
CVE-2026-33703

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/per…

Mitigation only
Fix from $1,600 2026-04-10
Chamilo Lms HIGH 7.1
CVE-2026-32894

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebo…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms HIGH 7.1
CVE-2026-32930

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebo…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-33141

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endp…

Fix: after 1.11.38
Fix from $1,600 2026-04-10
Couchcms HIGH 7.2
CVE-2026-29002

CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with th…

Fix: after 2.4
Fix from $1,950 2026-04-10
Directus HIGH 8.8
CVE-2026-39942

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-cont…

Fix: 11.17.0+
Fix from $1,950 2026-04-09
Unclassified HIGH 7.3
CVE-2026-5842

A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the compo…

Mitigation only
Fix from $1,950 2026-04-09
Inventree HIGH 8.1
CVE-2026-35478

InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token a…

Fix: after 1.2.6
Fix from $1,950 2026-04-08
Loris MEDIUM 6.5
CVE-2026-34985

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …

Fix: after 27.0.2
Fix from $1,600 2026-04-08
Loris MEDIUM 6.5
CVE-2026-35165

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …

Fix: after 27.0.2
Fix from $1,600 2026-04-08
Mirror Registry For Red Hat Openshift HIGH 7.4
CVE-2026-32589

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can inter…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-39616

Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Co…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-39526

Authorization Bypass Through User-Controlled Key vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control …

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-4654

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, a…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-5167

The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Cont…

Mitigation only
Fix from $1,600 2026-04-08
Plane HIGH 7.7
CVE-2026-39374

Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modi…

Fix: 1.3.0+
Fix from $1,950 2026-04-07
Scoold MEDIUM 6.5
CVE-2026-39354

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoold allows any logged-in, low-…

Fix: 1.66.2+
Fix from $1,600 2026-04-07
Churchcrm HIGH 8.1
CVE-2026-39331

ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper a…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Freescout HIGH 7.6
CVE-2026-39384

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_…

Fix: 1.8.212+
Fix from $1,950 2026-04-07
Freescout MEDIUM 6.5
CVE-2026-35584

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation_id}/…

Fix: 1.8.212+
Fix from $1,600 2026-04-07
Recipes HIGH 7.3
CVE-2026-35489

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping…

Fix: 2.6.4+
Fix from $1,950 2026-04-07
Unclassified HIGH 8.8
CVE-2026-5465

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up t…

Mitigation only
Fix from $1,950 2026-04-07
Bravecms MEDIUM 5.4
CVE-2026-35183

Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion featur…

Fix: 2.0.6+
Fix from $1,600 2026-04-06
Chyrp Lite MEDIUM 6.5
CVE-2026-35173

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authentica…

Fix: 2026.01+
Fix from $1,600 2026-04-06
Recipes HIGH 8.1
CVE-2026-35045

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update…

Fix: 2.6.4+
Fix from $1,950 2026-04-06
Lupa CRITICAL 10.0
CVE-2026-34444

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are acc…

Fix: after 2.6
Fix from $2,300 2026-04-06
Unclassified HIGH 8.1
CVE-2026-4896

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direc…

Mitigation only
Fix from $1,950 2026-04-04
Cloud Api HIGH 8.1
CVE-2026-25197

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

Fix: 2.12.2026+
Fix from $1,950 2026-04-03
Scoold MEDIUM 6.5
CVE-2026-34832

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback …

Fix: 1.66.1+
Fix from $1,600 2026-04-02
Listmonk MEDIUM 5.4
CVE-2026-34584

listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission check…

Fix: 6.1.0+
Fix from $1,600 2026-04-02