Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified MEDIUM 5.3
CVE-2026-5326

A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the file /index.php?page=manage_use…

Mitigation only
Fix from $1,600 2026-04-02
Mongoose HIGH 8.1
CVE-2026-5246

A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the co…

Fix: 7.21+
Fix from $1,950 2026-04-02
Openclaw MEDIUM 6.5
CVE-2026-32976

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration …

Fix: 2026.3.11+
Fix from $1,600 2026-03-31
Millie Chatbot MEDIUM 6.5
CVE-2026-4400

Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of other users being viewed by sim…

Fix: 3.6.0+
Fix from $1,600 2026-03-31
Nginx Ui CRITICAL 9.9
CVE-2026-33030

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) …

Fix: after 2.3.3
Fix from $2,300 2026-03-30
Unclassified HIGH 8.7
CVE-2026-3321

A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. Exploiting…

Mitigation only
Fix from $1,950 2026-03-30
Unclassified HIGH 7.5
CVE-2026-3124

The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the execu…

Mitigation only
Fix from $1,950 2026-03-30
Mcp Ruby Sdk MEDIUM 5.9
CVE-2026-33946

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamable_http_transpor…

Fix: 0.9.2+
Fix from $1,600 2026-03-27
Langflow Base HIGH 8.8
CVE-2026-34046

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/l…

Fix: 0.5.1 / 1.5.0+
Fix from $1,950 2026-03-27
Librechat MEDIUM 5.3
CVE-2026-31950

LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/api/agents/chat/stream/:…

No fix yet
Fix from $1,600 2026-03-27
Xagent MEDIUM 6.5
CVE-2026-4958

A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentSe…

No fix yet
Fix from $1,600 2026-03-27
Avideo MEDIUM 5.3
CVE-2026-33759

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full …

Fix: after 26.0
Fix from $1,600 2026-03-27
Unclassified CRITICAL 9.3
CVE-2026-1496

Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an aut…

Mitigation only
Fix from $2,300 2026-03-27
Open Source Point Of Sale MEDIUM 6.5
CVE-2026-33730

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2…

Fix: 3.4.2+
Fix from $1,600 2026-03-27
Mytube HIGH 8.8
CVE-2026-33735

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/impor…

Fix: 1.8.69+
Fix from $1,950 2026-03-27
Open Webui HIGH 7.1
CVE-2026-28788

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can…

Fix: 0.8.6+
Fix from $1,950 2026-03-27
Recipes MEDIUM 6.5
CVE-2026-28503

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the `SyncViewSet.que…

Fix: 2.6.0+
Fix from $1,600 2026-03-26
Openemr MEDIUM 6.3
CVE-2026-34055

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient…

Fix: 8.0.0.3+
Fix from $1,600 2026-03-26
Openemr MEDIUM 6.5
CVE-2026-33931

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct…

Fix: 8.0.0.3+
Fix from $1,600 2026-03-26
Openemr MEDIUM 6.3
CVE-2026-32120

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct…

Fix: 8.0.0.3+
Fix from $1,600 2026-03-25
Infosphere Information Server HIGH 7.5
CVE-2025-14974

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR).

Fix: after 11.7.1.6
Fix from $1,950 2026-03-25
N8n HIGH 7.4
CVE-2026-33724

n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configured to use SSH, the SSH command…

Fix: 2.5.0+
Fix from $1,950 2026-03-25
N8n MEDIUM 6.5
CVE-2026-33663

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` ro…

Fix: 1.123.27 / 2.13.3+
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-32535

Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Acc…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-32533

Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Contr…

Mitigation only
Fix from $1,600 2026-03-25
Hypr CRITICAL 9.8
CVE-2026-2414

Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.5.2 befor…

Fix: 10.7.2+
Fix from $2,300 2026-03-25
Unclassified HIGH 8.6
CVE-2025-69347

Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploiting Incorrectly Configured Ac…

Mitigation only
Fix from $1,950 2026-03-25
Pyload Ng CRITICAL 9.8
CVE-2026-33511

pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator i…

Fix: 0.5.0b3.dev97+
Fix from $2,300 2026-03-24
Solidtime MEDIUM 6.5
CVE-2026-33345

solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organizations/{org}/projects/{project…

Fix: 0.11.6+
Fix from $1,600 2026-03-24
Craft Cms MEDIUM 5.3
CVE-2026-33160

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …

Fix: 4.17.8 / 5.9.14+
Fix from $1,600 2026-03-24