Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Craft Cms MEDIUM 6.5
CVE-2026-33158

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …

Fix: 4.17.8 / 5.9.14+
Fix from $1,600 2026-03-24
Vikunja HIGH 8.1
CVE-2026-33678

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`W…

Fix: 2.2.1+
Fix from $1,950 2026-03-24
Langflow HIGH 7.5
CVE-2026-33484EPSS 6%

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{…

Fix: 1.9.0+
Fix from $1,950 2026-03-24
Connect Cms HIGH 8.1
CVE-2026-32300

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi…

Fix: 1.41.1 / 2.41.1+
Fix from $1,950 2026-03-23
Blinko MEDIUM 6.5
CVE-2026-23487

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.detail Endpoint Leaks the Superad…

Fix: 1.8.4+
Fix from $1,600 2026-03-23
Blinko MEDIUM 5.3
CVE-2026-23488

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an unauthorized access vulnerabilit…

Fix: 1.8.4+
Fix from $1,600 2026-03-23
New Api MEDIUM 6.5
CVE-2026-30886

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure…

Fix: 0.11.4+
Fix from $1,600 2026-03-23
Avideo CRITICAL 9.1
CVE-2026-33297

WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administr…

Fix: 26.0+
Fix from $2,300 2026-03-23
Discourse MEDIUM 5.3
CVE-2026-33425

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenticated users can determine whe…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-21
Langflow HIGH 8.8
CVE-2026-33053

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accept…

Fix: 1.9.0+
Fix from $1,950 2026-03-20
Filebrowser MEDIUM 6.5
CVE-2026-32761

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6…

Fix: 2.62.0+
Fix from $1,600 2026-03-20
Suitecrm HIGH 8.1
CVE-2026-29189

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the Sui…

Fix: 7.15.1 / 8.9.3+
Fix from $1,950 2026-03-20
Suitecrm MEDIUM 6.5
CVE-2026-32697

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, the `RecordHandler…

Fix: 8.9.3+
Fix from $1,600 2026-03-20
Openclaw MEDIUM 6.5
CVE-2026-32039

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers t…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openemr MEDIUM 6.5
CVE-2026-33304

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in…

Fix: 8.0.0.2+
Fix from $1,600 2026-03-19
Openemr MEDIUM 6.5
CVE-2026-25744

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API a…

Fix: 8.0.0.2+
Fix from $1,600 2026-03-19
Ecase Ecomplaint CRITICAL 9.8
CVE-2026-32867

OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files vi…

Fix: 10.1.0.0+
Fix from $2,300 2026-03-19
Unclassified MEDIUM 6.5
CVE-2025-32223

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2026-03-19
Unclassified MEDIUM 6.5
CVE-2026-27397

Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro allows Exploiting Incorrectly…

Mitigation only
Fix from $1,600 2026-03-19
Openemr MEDIUM 6.5
CVE-2026-25745

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the m…

Fix: after 8.0.0
Fix from $1,600 2026-03-18
Juju MEDIUM 6.6
CVE-2026-32694

In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a …

Fix: 3.6.19+
Fix from $1,600 2026-03-18
Unclassified CRITICAL 9.6
CVE-2026-30884

mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. P…

Patch available
Fix from $2,300 2026-03-18
Sentry MEDIUM 6.5
CVE-2026-26004

Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object…

Fix: 26.1.0+
Fix from $1,600 2026-03-18
Outline HIGH 8.8
CVE-2026-24901

Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the doc…

Fix: 1.4.0+
Fix from $1,950 2026-03-17
Mfa Mail HIGH 8.8
CVE-2026-4208

The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login at…

Fix: 1.0.7+
Fix from $1,950 2026-03-17
Unclassified MEDIUM 5.3
CVE-2025-69727

An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (index.js and composeUrlImgPho…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified MEDIUM 6.3
CVE-2026-4171

A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of t…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified HIGH 8.6
CVE-2026-3020

Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user account, such as changing th…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.5
CVE-2026-1947

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and…

Mitigation only
Fix from $1,950 2026-03-16
Sdt Cs3b1 Firmware CRITICAL 9.8
CVE-2017-20223

Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass…

Mitigation only
Fix from $2,300 2026-03-16