Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.1 CVE-2026-8406 openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the mes… Patch available Fix from $1,9502026-06-11 HIGH 8.7 CVE-2026-6552 GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under … GitLab 18.10.8 / 18.11.5+ Fix from $1,9502026-06-11 MEDIUM 6.3 CVE-2026-53911 Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operations and certain custom en… Patch available Fix from $1,6002026-06-11 MEDIUM 5.3 CVE-2023-40200 Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting … Mitigation only Fix from $1,6002026-06-11 HIGH 7.7 CVE-2026-44692 Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that autho… Mitigation only Fix from $1,9502026-06-10 HIGH 8.3 CVE-2026-46558 Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated… Plane 1.3.1+ Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-53470 A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/… Migration Assessment 0.13.5+ Fix from $1,9502026-06-10 HIGH 7.7 CVE-2026-53471 A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory an… Migration Assessment 0.13.5+ Fix from $1,9502026-06-10 CRITICAL 9.1 CVE-2026-45550 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smo… Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-45552 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares … Mitigation only Fix from $2,3002026-06-10 HIGH 8.1 CVE-2026-53673 BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access a… Mitigation only Fix from $1,9502026-06-10 HIGH 8.6 CVE-2026-6444 A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functio… Mitigation only Fix from $1,9502026-06-09 CRITICAL 9.8 CVE-2026-44083 An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vuln… Qumagie 2.9.0+ Fix from $2,3002026-06-09 HIGH 7.5 CVE-2026-9185 The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.… Mitigation only Fix from $1,9502026-06-09 HIGH 7.1 CVE-2026-49141 WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access an… Patch available Fix from $1,9502026-06-08 CRITICAL 9.6 CVE-2026-46441 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis… Flowise 3.1.2+ Fix from $2,3002026-06-08 CRITICAL 9.6 CVE-2026-42861 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis… Flowise 3.1.2+ Fix from $2,3002026-06-08 MEDIUM 5.0 CVE-2026-42862 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis… Flowise 3.1.2+ Fix from $1,6002026-06-08 HIGH 8.1 CVE-2026-42863 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis… Flowise 3.1.2+ Fix from $1,9502026-06-08 MEDIUM 5.0 CVE-2026-11500 A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authenticat… Patch available Fix from $1,6002026-06-08 MEDIUM 6.3 CVE-2026-11461 A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state… Mitigation only Fix from $1,6002026-06-07 HIGH 7.2 CVE-2026-9851 The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is… Mitigation only Fix from $1,9502026-06-06 MEDIUM 5.3 CVE-2026-8839 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and inc… Mitigation only Fix from $1,6002026-06-06 MEDIUM 5.3 CVE-2026-7665EPSS 7% The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions… Mitigation only Fix from $1,6002026-06-06 MEDIUM 6.9 CVE-2026-46390 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0.0, the gitlist plugin is exp… Mitigation only Fix from $1,6002026-06-05 CRITICAL 9.0 CVE-2026-45750 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fi… Termix 2.3.2+ Fix from $2,3002026-06-05 CRITICAL 9.0 CVE-2026-45746 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manage… Termix 2.3.2+ Fix from $2,3002026-06-05 HIGH 8.1 CVE-2026-45743 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-manager endpoints in Termix pri… Termix 2.3.2+ Fix from $1,9502026-06-05 HIGH 7.1 CVE-2026-11369 The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization checks to verify that the request… Mitigation only Fix from $1,9502026-06-05 MEDIUM 6.5 CVE-2026-11142 Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04