Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 8.7 CVE-2026-53729 DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (/exportCenter/download/{id}),… Patch available Fix from $1,9502026-07-07 MEDIUM 6.5 CVE-2026-49296 Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/… Airflow 3.3.0+ Fix from $1,6002026-07-07 HIGH 7.5 CVE-2026-5730 Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted… Mitigation only Fix from $1,9502026-07-07 HIGH 7.5 CVE-2026-5799 Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted… Mitigation only Fix from $1,9502026-07-07 HIGH 7.1 CVE-2026-57868 MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0… Mitigation only Fix from $1,9502026-07-07 HIGH 7.1 CVE-2026-57869 Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access … Mitigation only Fix from $1,9502026-07-07 MEDIUM 5.3 CVE-2026-57870 Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations… Mitigation only Fix from $1,6002026-07-07 CRITICAL 9.9 CVE-2026-34037 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire a… Patch available Fix from $2,3002026-07-07 HIGH 7.7 CVE-2026-34044 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the Logs::mount() compon… Patch available Fix from $1,9502026-07-07 HIGH 8.7 CVE-2026-53643 FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unaut… Mitigation only Fix from $1,9502026-07-06 HIGH 8.6 CVE-2026-53644 FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticated clients to both read and re… Mitigation only Fix from $1,9502026-07-06 MEDIUM 5.0 CVE-2026-34167 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the ActivityMonitor Live… Patch available Fix from $1,6002026-07-06 HIGH 8.1 CVE-2026-59712 Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential… Patch available Fix from $1,9502026-07-06 CRITICAL 9.3 CVE-2026-12686 An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted … Mitigation only Fix from $2,3002026-07-06 MEDIUM 5.3 CVE-2026-48206 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component. The camel-jira producers r… Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 MEDIUM 5.3 CVE-2026-49099 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key … Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 HIGH 7.5 CVE-2026-46585 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene produce… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 MEDIUM 5.3 CVE-2026-46453 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elast… Camel 4.14.8 / 4.18.3+ Fix from $1,6002026-07-06 HIGH 7.3 CVE-2026-14753 A vulnerability was detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This impacts an unknown function of the file /PHP… Mitigation only Fix from $1,9502026-07-05 HIGH 7.1 CVE-2026-28740 Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lac… Patch available Fix from $1,9502026-07-03 MEDIUM 5.3 CVE-2026-25782 Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion at… Patch available Fix from $1,6002026-07-03 HIGH 7.5 CVE-2026-27657 Gitea versions before 1.25.5 allow a user to change another user's primary email address. Patch available Fix from $1,9502026-07-03 MEDIUM 5.4 CVE-2026-14614 A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue al… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $1,6002026-07-03 MEDIUM 6.9 CVE-2026-59234 Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventControl… Patch available Fix from $1,6002026-07-03 MEDIUM 5.3 CVE-2026-9180 The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and i… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.5 CVE-2026-59098 LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic search functionality that allows… Patch available Fix from $1,6002026-07-02 MEDIUM 5.0 CVE-2026-59100 LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other user… Patch available Fix from $1,6002026-07-02 MEDIUM 5.9 CVE-2026-58580 LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, upda… Mitigation only Fix from $1,6002026-07-02 MEDIUM 6.5 CVE-2026-57680 Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions. Mitigation only Fix from $1,6002026-07-02 MEDIUM 5.3 CVE-2026-9188 The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ve… Mitigation only Fix from $1,6002026-07-02