Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 8.7
CVE-2026-47743

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive da…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-47755

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged auth…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-65696

Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenti…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 8.8
CVE-2026-65917

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's …

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65501

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-65463

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-61946

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

No fix yet
Fix from $1,600 2026-07-23
Sterling B2b Integrator MEDIUM 5.3
CVE-2026-3482

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could…

Fix: after 6.2.2.0_1
Fix from $1,600 2026-07-22
Unclassified CRITICAL 9.6
CVE-2026-16624

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated tea…

No fix yet
Fix from $2,300 2026-07-22
Unclassified HIGH 8.8
CVE-2026-65013

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to acc…

No fix yet
Fix from $1,950 2026-07-22
N8n HIGH 8.8
CVE-2026-65016

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provi…

Fix: 1.123.64 / 2.29.8+
Fix from $1,950 2026-07-22
Unclassified MEDIUM 6.5
CVE-2026-2406

Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration an…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.5
CVE-2026-65316

XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from j…

No fix yet
Fix from $1,600 2026-07-21
Irecruitment MEDIUM 5.4
CVE-2026-61064

Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supported versions that are affec…

Fix: after 12.2.15
Fix from $1,600 2026-07-21
Kibana HIGH 7.1
CVE-2026-56147

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity co…

Fix: 8.19.18 / 9.3.7+
Fix from $1,950 2026-07-21
Unclassified HIGH 7.6
CVE-2026-47414

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 8.3
CVE-2026-47415

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 8.1
CVE-2026-47417

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…

Mitigation only
Fix from $1,950 2026-07-21
Unclassified HIGH 8.1
CVE-2026-47418

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 8.3
CVE-2026-47419

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Referenc…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 8.1
CVE-2026-47406

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.4
CVE-2026-47407

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources un…

No fix yet
Fix from $2,300 2026-07-21
Unclassified MEDIUM 6.5
CVE-2026-47408

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 8.8
CVE-2026-47399

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain…

Mitigation only
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.5
CVE-2026-15342

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or…

No fix yet
Fix from $1,600 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28317

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires …

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28313

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary accoun…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28314

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28316

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administr…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28305

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain ac…

Fix: 2026.3+
Fix from $2,300 2026-07-21