Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Serv U CRITICAL 9.1
CVE-2026-28308

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrato…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28302

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execu…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Unclassified MEDIUM 5.4
CVE-2026-14184

The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, al…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 7.6
CVE-2026-55544

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write oper…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-57494

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated Agent…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.5
CVE-2026-47198

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.4
CVE-2026-44585

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint acc…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.1
CVE-2026-47130

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR)…

No fix yet
Fix from $1,950 2026-07-20
Clinic HIGH 8.1
CVE-2026-13381

VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-45295

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/…

No fix yet
Fix from $1,600 2026-07-20
Surrealdb HIGH 8.8
CVE-2026-63763

SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with th…

Fix: 2.5.0+
Fix from $1,950 2026-07-20
Surrealdb MEDIUM 5.4
CVE-2026-63745

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb HIGH 8.1
CVE-2026-63735

SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints …

Fix: 3.2.0+
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-16217

A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file d…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-16214

A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the compon…

No fix yet
Fix from $1,600 2026-07-19
Unclassified CRITICAL 9.6
CVE-2026-55518

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_…

No fix yet
Fix from $2,300 2026-07-17
Langflow HIGH 8.1
CVE-2026-13445

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploa…

Fix: 1.10.2+
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-63307

Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{id} endpoint. The handler call…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-11763

Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. Gi…

No fix yet
Fix from $1,600 2026-07-17
Unclassified CRITICAL 9.4
CVE-2026-12693

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly…

No fix yet
Fix from $2,300 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-63099

TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated …

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-63095

Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to …

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.1
CVE-2026-22104

Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read …

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.4
CVE-2026-12393

The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-11966

The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membe…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 8.8
CVE-2026-62233

grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.user…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 7.5
CVE-2026-43977

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout ses…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-11889

SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an aut…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.3
CVE-2026-53536

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JW…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.9
CVE-2026-59237

Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 a…

No fix yet
Fix from $1,600 2026-07-16