Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 7.5
CVE-2026-68500

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_lo…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-68501

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_loc…

No fix yet
Fix from $1,600 2026-07-30
Langflow MEDIUM 6.5
CVE-2026-10700

IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access …

Fix: 1.9.0+
Fix from $1,600 2026-07-30
Langflow HIGH 7.1
CVE-2026-12945

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on …

Fix: 1.10.2+
Fix from $1,950 2026-07-30
Unclassified HIGH 8.1
CVE-2026-15658

A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of o…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 8.1
CVE-2026-67348

Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read anot…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-15255

The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the ident…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-15257

The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing ac…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 5.4
CVE-2026-14310

The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning o…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.5
CVE-2026-13178

The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauth…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-13345

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCom…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.5
CVE-2025-60931

An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attacker…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-5060

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 5.4
CVE-2026-14224

The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 8.8
CVE-2026-57510

SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated user…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-49258

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-oper…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.9
CVE-2026-59240

The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notifi…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.4
CVE-2026-48052

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organizatio…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.0
CVE-2026-17531

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/route…

No fix yet
Fix from $1,600 2026-07-27
Unclassified HIGH 7.5
CVE-2026-59539

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.4
CVE-2026-59546

Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.7
CVE-2026-17527

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, include…

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-66412

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are…

No fix yet
Fix from $1,600 2026-07-27
Unclassified CRITICAL 9.3
CVE-2026-66013

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to upd…

No fix yet
Fix from $2,300 2026-07-25
Unclassified HIGH 8.1
CVE-2026-65708

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account fi…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.3
CVE-2026-65709

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enume…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.1
CVE-2026-65710

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag…

No fix yet
Fix from $1,950 2026-07-24
Build Of Keycloak MEDIUM 6.5
CVE-2026-17059

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access managem…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.3
CVE-2026-13464

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version…

No fix yet
Fix from $1,600 2026-07-24
Unclassified CRITICAL 9.9
CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a…

No fix yet
Fix from $2,300 2026-07-23