Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Streaming Engine HIGH 7.8
CVE-2016-20033

Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing …

No fix yet
Fix from $1,950 2026-03-16
Id Server HIGH 8.8
CVE-2026-3999

A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability only impacts specific confi…

Fix: 9.0.0+
Fix from $1,950 2026-03-13
Unclassified MEDIUM 5.4
CVE-2026-2879

The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.2. This is due to missi…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.3
CVE-2026-2888

The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, …

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.4
CVE-2026-2257

The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.2 due to missing valida…

Mitigation only
Fix from $1,600 2026-03-13
Winter CRITICAL 9.9
CVE-2026-27591

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS al…

Fix: 1.0.477 / 1.1.12+
Fix from $2,300 2026-03-11
Zitadel HIGH 7.7
CVE-2026-32131

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, whi…

Fix: 3.4.8 / 4.12.2+
Fix from $1,950 2026-03-11
Studiocms HIGH 7.2
CVE-2026-32103

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studiocms_api/dashboard/create-reset…

Fix: 0.4.3+
Fix from $1,950 2026-03-11
Studiocms MEDIUM 5.4
CVE-2026-32104

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the updateUserNotifications endpoint accepts a…

Fix: 0.4.3+
Fix from $1,600 2026-03-11
Pingpong HIGH 8.8
CVE-2026-32097

PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticated user may be able to retrie…

Fix: 7.27.2+
Fix from $1,950 2026-03-11
Unclassified CRITICAL 9.8
CVE-2019-25487EPSS 8%

SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands b…

Mitigation only
Fix from $2,300 2026-03-11
Taskosaur CRITICAL 9.8
CVE-2026-31874

Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly…

Patch available
Fix from $2,300 2026-03-11
Classroomio HIGH 8.1
CVE-2025-67298

An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile

Fix: 0.2.6+
Fix from $1,950 2026-03-11
Unclassified HIGH 8.8
CVE-2026-1992

The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2.…

Mitigation only
Fix from $1,950 2026-03-11
Unclassified MEDIUM 5.4
CVE-2026-2917

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 vi…

Mitigation only
Fix from $1,600 2026-03-11
Unclassified MEDIUM 6.4
CVE-2026-2918

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 vi…

Mitigation only
Fix from $1,600 2026-03-11
Unclassified MEDIUM 6.8
CVE-2026-1753

The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbit…

Mitigation only
Fix from $1,600 2026-03-11
Unclassified HIGH 8.1
CVE-2026-3453

The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to…

Mitigation only
Fix from $1,950 2026-03-11
Umbraco Cms MEDIUM 5.4
CVE-2026-31832

Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability exists in a backoffice API endp…

Fix: 16.5.1 / 17.2.2+
Fix from $1,600 2026-03-10
Sylius MEDIUM 6.5
CVE-2026-31820

Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulnerability exists in multiple sh…

Fix: 2.0.16 / 2.1.12+
Fix from $1,600 2026-03-10
Oneuptime MEDIUM 5.0
CVE-2026-30959

OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a…

Fix: 10.0.21+
Fix from $1,600 2026-03-10
Coral Server CRITICAL 9.1
CVE-2026-30969

Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1…

Fix: 1.1.0+
Fix from $2,300 2026-03-10
Studiocms HIGH 8.8
CVE-2026-30944

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoi…

Fix: 0.4.0+
Fix from $1,950 2026-03-10
Studiocms HIGH 7.1
CVE-2026-30945

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens…

Fix: 0.4.0+
Fix from $1,950 2026-03-10
Oneuptime HIGH 8.6
CVE-2026-30920

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled sta…

Fix: 10.0.19+
Fix from $1,950 2026-03-10
Admidio MEDIUM 5.4
CVE-2026-30927

Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any u…

Fix: 5.0.6+
Fix from $1,600 2026-03-10
Avideo MEDIUM 5.3
CVE-2026-30885

WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user with…

Fix: 25.0+
Fix from $1,600 2026-03-10
Freshrss HIGH 7.5
CVE-2025-62166

FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is …

Fix: 1.28.0+
Fix from $1,950 2026-03-09
Weknora MEDIUM 5.3
CVE-2026-30857

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authoriza…

Fix: 0.3.0+
Fix from $1,600 2026-03-07
Flowise HIGH 8.8
CVE-2026-30823

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, lea…

Fix: 3.0.13+
Fix from $1,950 2026-03-07