Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.3 CVE-2026-54105 The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic D… Mitigation only Fix from $1,6002026-06-18 HIGH 7.1 CVE-2026-50141 Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any authen… Patch available Fix from $1,9502026-06-18 HIGH 7.1 CVE-2026-48759 TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability through cross-workspace Theme Tem… Mitigation only Fix from $1,9502026-06-17 HIGH 8.2 CVE-2026-50194 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management… Patch available Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2026-55197 Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose … Patch available Fix from $1,6002026-06-17 MEDIUM 6.5 CVE-2026-55198 Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access … Patch available Fix from $1,6002026-06-17 MEDIUM 5.3 CVE-2025-15657 Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions. Mitigation only Fix from $1,6002026-06-17 HIGH 8.2 CVE-2026-54184 Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 7.3 CVE-2026-40768 Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions. Mitigation only Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2026-53863 OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who ca… Openclaw 2026.4.25+ Fix from $1,6002026-06-16 HIGH 7.6 CVE-2026-48599 Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belon… Patch available Fix from $1,9502026-06-15 HIGH 7.5 CVE-2026-52699 Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.5 CVE-2026-48868 Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.5 CVE-2026-48872 Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions. Mitigation only Fix from $1,9502026-06-15 MEDIUM 6.3 CVE-2026-40792 Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions. Mitigation only Fix from $1,6002026-06-15 HIGH 7.1 CVE-2026-39518 Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.5 CVE-2025-59133 Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.3 CVE-2026-12204 A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveInteg… Mitigation only Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-54361 MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Se… Patch available Fix from $1,9502026-06-12 MEDIUM 5.1 CVE-2026-54357 An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to si… Patch available Fix from $1,6002026-06-12 HIGH 8.4 CVE-2026-54360 A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a … Patch available Fix from $1,9502026-06-12 MEDIUM 6.9 CVE-2026-53726 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a… Patch available Fix from $1,6002026-06-12 HIGH 8.8 CVE-2026-42947 A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbi… Mitigation only Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-8828 A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, … Mitigation only Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-45830 A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, writ… Chromadb after 1.5.9 Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-45832 All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers t… Chromadb after 1.5.9 Fix from $1,9502026-06-12 MEDIUM 6.9 CVE-2026-44207 Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access … Mitigation only Fix from $1,6002026-06-12 MEDIUM 6.5 CVE-2026-47238 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subt… Mitigation only Fix from $1,6002026-06-11 HIGH 8.3 CVE-2026-47189 Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the AutoMod remove flow looks up a… Mitigation only Fix from $1,9502026-06-11 HIGH 8.1 CVE-2026-7787 IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using inse… Langflow 1.9.2+ Fix from $1,9502026-06-11