Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2026-58447 Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attacke… Patch available Fix from $1,6002026-06-30 CRITICAL 9.6 CVE-2026-10140 IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. A… Langflow after 1.10.0 Fix from $2,3002026-06-30 MEDIUM 5.0 CVE-2026-27881 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/deployments… Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.0 CVE-2026-27883 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deploym… Mitigation only Fix from $1,6002026-06-30 CRITICAL 9.8 CVE-2026-12073 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versio… Mitigation only Fix from $2,3002026-06-30 HIGH 7.7 CVE-2026-34592 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, Coolify server and proje… Mitigation only Fix from $1,9502026-06-29 CRITICAL 9.6 CVE-2026-57498 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controller… Mitigation only Fix from $2,3002026-06-29 MEDIUM 6.4 CVE-2026-57956 SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by su… Patch available Fix from $1,6002026-06-29 MEDIUM 5.9 CVE-2026-57943 LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users t… Patch available Fix from $1,6002026-06-29 HIGH 7.5 CVE-2026-56780 Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domai… Patch available Fix from $1,9502026-06-29 MEDIUM 5.3 CVE-2026-56781 Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data… Patch available Fix from $1,6002026-06-29 MEDIUM 6.5 CVE-2026-57341 Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions. Mitigation only Fix from $1,6002026-06-29 MEDIUM 5.4 CVE-2026-13549 A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file appli… Mitigation only Fix from $1,6002026-06-29 MEDIUM 5.0 CVE-2026-13534 A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryServi… Patch available Fix from $1,6002026-06-29 MEDIUM 6.3 CVE-2026-13512 A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/ser… Patch available Fix from $1,6002026-06-28 MEDIUM 5.4 CVE-2026-52779 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion… Mitigation only Fix from $1,6002026-06-26 CRITICAL 9.9 CVE-2026-52782 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/projec… Mitigation only Fix from $2,3002026-06-26 MEDIUM 6.5 CVE-2026-44736 OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user … Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2026-56823 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/… Mitigation only Fix from $1,6002026-06-26 CRITICAL 9.6 CVE-2026-12411 Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gu… Lxd 6.9+ Fix from $2,3002026-06-26 MEDIUM 5.3 CVE-2026-57665 Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.3 CVE-2026-57652 Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2026-57646 Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.3 CVE-2026-57630 Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-56069 Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-56048 Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-54839 Unauthenticated Sensitive Data Exposure in Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups <= 2.0.9 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.6 CVE-2026-54826 Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.3 CVE-2025-66123 Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2026-56774 Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to R… Patch available Fix from $1,6002026-06-25