Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 7.5
CVE-2026-65523

Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-28180

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-14313

PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-wooco…

No fix yet
Fix from $1,600 2026-08-06
Langflow HIGH 7.1
CVE-2026-9130

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Answer MEDIUM 6.5
CVE-2026-48912

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar…

Fix: 2.0.2+
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71251

Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth mid…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.3
CVE-2026-71242

Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePol…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.3
CVE-2026-55739

Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->compan…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-11454

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.3
CVE-2026-16981

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or owne…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.3
CVE-2026-18818

A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 8.3
CVE-2026-70476

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in pa…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-69258

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.5
CVE-2026-69250

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18722

A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18631

A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/sr…

No fix yet
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-2346

Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affe…

No fix yet
Fix from $2,300 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-68582

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1…

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 7.1
CVE-2025-71400

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows auth…

No fix yet
Fix from $1,950 2026-08-02
Unclassified CRITICAL 9.8
CVE-2026-67342

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoi…

No fix yet
Fix from $2,300 2026-08-01
Unclassified HIGH 7.1
CVE-2026-67329

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscri…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.3
CVE-2026-67331

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authentic…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 5.3
CVE-2025-14073

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.1
CVE-2026-65981

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH reque…

No fix yet
Fix from $1,950 2026-07-31
Pgadmin 4 CRITICAL 9.6
CVE-2026-17349

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones th…

Fix: 9.17+
Fix from $2,300 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-17567

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.4
CVE-2026-8155

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated …

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-15209

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-14843

The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an un…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.4
CVE-2026-12697

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messag…

No fix yet
Fix from $1,600 2026-07-31