Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 7.6
CVE-2025-71388

stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that ch…

No fix yet
Fix from $1,950 2026-07-16
Dfx Server HIGH 8.2
CVE-2026-35147

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication s…

Fix: after 2.5
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.9
CVE-2026-12510

The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, al…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.3
CVE-2026-15909

A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the fil…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.5
CVE-2026-55234

Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.j…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.5
CVE-2026-53447

Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoard…

Mitigation only
Fix from $1,600 2026-07-15
N8n Mcp CRITICAL 9.9
CVE-2026-54052

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with…

Fix: 2.56.1+
Fix from $2,300 2026-07-15
Mcp Python Sdk HIGH 7.1
CVE-2026-52869

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streama…

Fix: 1.27.2+
Fix from $1,950 2026-07-15
Unclassified HIGH 8.1
CVE-2026-58660

Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the c…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.7
CVE-2026-48799

Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provi…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.5
CVE-2025-32781

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified CRITICAL 9.9
CVE-2026-44986

Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from …

Mitigation only
Fix from $2,300 2026-07-15
Directus HIGH 8.6
CVE-2026-61836

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key der…

Fix: 12.0.0+
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.9
CVE-2026-59236

Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prosper…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 6.3
CVE-2026-59254

n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outsi…

Mitigation only
Fix from $1,600 2026-07-15
N8n MEDIUM 6.5
CVE-2026-59259

n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between…

Fix: 1.123.61 / 2.27.4+
Fix from $1,600 2026-07-15
Unclassified HIGH 8.7
CVE-2026-59235

Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /ap…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.5
CVE-2026-11580

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-dupli…

Mitigation only
Fix from $1,600 2026-07-15
Rclone HIGH 8.8
CVE-2026-59733

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --…

Fix: 1.74.4+
Fix from $1,950 2026-07-14
Devolutions Server HIGH 7.5
CVE-2026-15637

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated lo…

Fix: 2026.1.23.0 / 2026.2.12.0+
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.9
CVE-2026-52837

Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/r…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 8.7
CVE-2026-15389

A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time web application and its REST…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 5.3
CVE-2026-15622

A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace…

Patch available
Fix from $1,600 2026-07-14
Unclassified HIGH 7.1
CVE-2026-58410

ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which al…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.5
CVE-2026-57694

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 7.5
CVE-2026-14165

An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker …

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 5.6
CVE-2026-15516

A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php …

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 7.1
CVE-2026-55880

OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the owners…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.1
CVE-2026-55881

OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session'…

Patch available
Fix from $1,950 2026-07-10
Snipe It MEDIUM 5.0
CVE-2026-55515

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and dele…

Fix: 8.6.2+
Fix from $1,600 2026-07-10