Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified MEDIUM 6.5
CVE-2026-69114

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers t…

No fix yet
Fix from $4,000 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72863

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au…

No fix yet
Fix from $5,750 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-68870

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-ag…

No fix yet
Fix from $4,000 2026-08-10
Apache Airflow Providers Apache Yandex MEDIUM 6.5
CVE-2026-68871

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo…

No fix yet
Fix from $4,000 2026-08-10
Apache Airflow Providers Amazon MEDIUM 6.5
CVE-2026-68872

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl…

No fix yet
Fix from $4,000 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72737

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs …

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 8.4
CVE-2026-72734

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 8.6
CVE-2026-19433

Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated us…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72689

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read com…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.1
CVE-2026-72690

An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory su…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 8.7
CVE-2026-59233

Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72564

An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in …

No fix yet
Fix from $5,750 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-19077

The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing an…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-15238

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticat…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-16574

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belong…

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 8.8
CVE-2026-48169

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break wo…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.5
CVE-2026-70561

TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege gues…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-66058

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is poss…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.5
CVE-2026-16039

The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated us…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.5
CVE-2026-70557

diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those …

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.9
CVE-2026-67622

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attac…

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-64662

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view con…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 8.5
CVE-2026-45414

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to th…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.1
CVE-2026-19111

Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-14842

The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauth…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-15147

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to v…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.5
CVE-2026-13399

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unau…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-10599

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order bein…

No fix yet
Fix from $1,950 2026-08-06
Escriptorium HIGH 8.8
CVE-2026-18258

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows …

No fix yet
Fix from $1,950 2026-08-06
Escriptorium MEDIUM 6.5
CVE-2026-18275

Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to…

No fix yet
Fix from $1,600 2026-08-06