Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Hoppscotch MEDIUM 6.5
CVE-2026-30825

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authentica…

Fix: 2026.2.1+
Fix from $1,600 2026-03-07
Flare HIGH 7.5
CVE-2026-30230

Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the thumbnail endpoint d…

Fix: 1.7.2+
Fix from $1,950 2026-03-06
Flare MEDIUM 5.3
CVE-2026-30231

Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the raw and direct file …

Fix: 1.7.2+
Fix from $1,600 2026-03-06
Wekan MEDIUM 6.5
CVE-2026-30843

Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which cou…

Patch available
Fix from $1,600 2026-03-06
Chartbrew MEDIUM 6.5
CVE-2026-25877

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1…

Fix: 4.8.1+
Fix from $1,600 2026-03-06
Openclaw HIGH 7.5
CVE-2026-28469

OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy co…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Vaultwarden MEDIUM 5.4
CVE-2026-27898

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated r…

Fix: 1.35.4+
Fix from $1,600 2026-03-04
Craft Cms MEDIUM 5.3
CVE-2026-29069

Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauth…

Fix: 4.17.0 / 5.9.0+
Fix from $1,600 2026-03-04
Craft Cms HIGH 7.5
CVE-2026-28696

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal ref…

Fix: 4.17.0 / 5.9.0+
Fix from $1,950 2026-03-04
Craft Cms MEDIUM 6.5
CVE-2026-28781

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the aut…

Fix: 4.17.0 / 5.9.0+
Fix from $1,600 2026-03-04
Android HIGH 8.4
CVE-2026-0020

In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions …

Mitigation only
Fix from $1,950 2026-03-02
Nocodb MEDIUM 6.3
CVE-2026-28361

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not validate token ownership, allowing…

Fix: 0.301.3+
Fix from $1,600 2026-03-02
Clininet HIGH 7.5
CVE-2025-58402

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter i…

Fix: 2025.ms4+
Fix from $1,950 2026-03-02
Clipbucket MEDIUM 6.5
CVE-2026-28354

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws,…

Fix: 5.5.3-59+
Fix from $1,600 2026-02-27
Seerr MEDIUM 6.5
CVE-2026-27793

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `GET /api/v1/user/:id` endpoint…

Fix: 3.1.0+
Fix from $1,600 2026-02-27
Openemr HIGH 7.1
CVE-2026-25147

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_pa…

Fix: 8.0.0+
Fix from $1,950 2026-02-27
Unclassified MEDIUM 5.3
CVE-2026-1558

The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This i…

Mitigation only
Fix from $1,600 2026-02-27
Hoppscotch HIGH 8.3
CVE-2026-28216

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's perso…

Fix: 2026.2.0+
Fix from $1,950 2026-02-26
Hoppscotch MEDIUM 6.5
CVE-2026-28217

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection…

Fix: 2026.2.0+
Fix from $1,600 2026-02-26
Manyfold MEDIUM 6.5
CVE-2026-28225

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version…

Fix: 0.133.1+
Fix from $1,600 2026-02-26
Unclassified HIGH 7.5
CVE-2026-27449

Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where c…

Mitigation only
Fix from $1,950 2026-02-26
Discourse HIGH 7.5
CVE-2026-26265

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items en…

Fix: 2025.12.0 / 2026.1.1+
Fix from $1,950 2026-02-26
Discourse HIGH 7.5
CVE-2026-26078

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting …

Fix: 2025.12.0 / 2026.1.1+
Fix from $1,950 2026-02-26
Openemr MEDIUM 6.5
CVE-2026-27943

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the e…

Fix: after 8.0.0
Fix from $1,600 2026-02-26
Openemr MEDIUM 6.5
CVE-2026-25930

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Layout-Based For…

Fix: 8.0.0+
Fix from $1,600 2026-02-25
Openemr HIGH 7.1
CVE-2026-25927

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the DICOM viewer st…

Fix: 8.0.0+
Fix from $1,950 2026-02-25
Openemr MEDIUM 6.5
CVE-2026-25929

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the document control…

Fix: 8.0.0+
Fix from $1,600 2026-02-25
Openemr MEDIUM 6.5
CVE-2026-25220

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Message Center a…

Fix: 8.0.0+
Fix from $1,600 2026-02-25
Plane MEDIUM 6.5
CVE-2026-27705

Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/as…

Fix: 1.2.2+
Fix from $1,600 2026-02-25
Sz Boot Parent MEDIUM 5.3
CVE-2026-3185

A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the…

Fix: after 0.9.0
Fix from $1,600 2026-02-25