Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.3 CVE-2026-71417 Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using … Fix unknown Fix from $4,9002026-08-18 HIGH 8.1 CVE-2026-71308 Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements ide… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.9 CVE-2026-55166 Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-si… Fix unknown Fix from $5,7502026-08-18 MEDIUM 6.5 CVE-2026-69160 OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use st… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-50167 Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpoints for listing and retrievi… Fix unknown Fix from $4,0002026-08-18 HIGH 8.8 CVE-2026-61574 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpo… Fix unknown Fix from $4,9002026-08-18 HIGH 8.3 CVE-2026-49225 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revis… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-49228 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product opera… Fix unknown Fix from $4,9002026-08-18 HIGH 7.6 CVE-2026-19869 @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-le… Fix unknown Fix from $4,9002026-08-18 HIGH 7.6 CVE-2026-49222 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product quest… Fix unknown Fix from $4,9002026-08-18 HIGH 7.6 CVE-2026-49223 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revie… Fix unknown Fix from $4,9002026-08-18 HIGH 8.3 CVE-2026-49224 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post revision… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-49221 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset… Fix unknown Fix from $4,9002026-08-18 HIGH 8.3 CVE-2026-49226 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post operatio… Fix unknown Fix from $4,9002026-08-18 HIGH 7.6 CVE-2026-49227 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment opera… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.4 CVE-2026-45120 MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users w… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-74009 Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-73395 Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-73189 Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions. Fix unknown Fix from $4,0002026-08-18 HIGH 7.6 CVE-2026-69189 Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, c… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-16309 Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-63178 Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/u… Fix unknown Fix from $4,0002026-08-17 HIGH 8.8 CVE-2026-75103 Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's… Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-75105 phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/ind… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-63669 ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destinati… Fix unknown Fix from $4,0002026-08-17 HIGH 8.8 CVE-2026-74877 openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clien… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.3 CVE-2026-19994 A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-… Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.3 CVE-2026-14832 The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup e… Fix unknown Fix from $4,0002026-08-17 HIGH 8.3 CVE-2026-19979 A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, M… Fix unknown Fix from $4,9002026-08-17 MEDIUM 5.4 CVE-2026-19966 A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/… Fix unknown Fix from $4,0002026-08-17