Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.4 CVE-2026-49192 The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device d… Connect M6e 5g Firmware Mitigation only Fix from $1,6002026-06-04 MEDIUM 5.3 CVE-2026-10597 OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific… Mitigation only Fix from $1,6002026-06-04 HIGH 8.8 CVE-2025-14772 Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. T Mac Plus Mitigation only Fix from $1,9502026-06-03 HIGH 8.8 CVE-2026-7201 CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, an… Sitefinity 15.2.8441 / 15.3.8531+ Fix from $1,9502026-06-02 MEDIUM 6.5 CVE-2026-24753 Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data … Kiteworks 9.3.0+ Fix from $1,6002026-06-01 MEDIUM 5.4 CVE-2026-24755 Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data … Kiteworks 9.3.0+ Fix from $1,6002026-06-01 MEDIUM 6.8 CVE-2026-45810 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, … Nextcloud Server 21.0.9.20 / 22.2.10.35+ Fix from $1,6002026-06-01 HIGH 8.1 CVE-2026-45281 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, w… Nextcloud Server 21.0.9.23 / 22.2.10.39+ Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-23638 Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data … Kiteworks 9.3.0+ Fix from $1,6002026-06-01 HIGH 7.5 CVE-2026-41084 A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization a… Airflow 3.2.2+ Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10212 A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. … Mitigation only Fix from $1,6002026-06-01 HIGH 8.7 CVE-2026-47266 Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a kno… Mitigation only Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2026-49386 In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas Youtrack 2026.1.13570+ Fix from $1,6002026-05-29 MEDIUM 5.3 CVE-2026-43917 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware only verifies the user is aut… Mitigation only Fix from $1,6002026-05-29 MEDIUM 5.1 CVE-2026-45551 Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authen… Mitigation only Fix from $1,6002026-05-29 MEDIUM 6.5 CVE-2026-9493 Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attacke… Mitigation only Fix from $1,6002026-05-29 HIGH 7.1 CVE-2026-45342 LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains an Insecure Direct Object Reference vulnerability in the … Mitigation only Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-42999 An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON re… Keystone 27.0.2 / 28.0.2+ Fix from $1,9502026-05-28 MEDIUM 5.3 CVE-2026-45297 OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_… Mitigation only Fix from $1,6002026-05-28 MEDIUM 6.5 CVE-2026-41141 EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:id/prepare endpoint accepts a… Mitigation only Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-7651 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Buil… Mitigation only Fix from $1,6002026-05-28 MEDIUM 6.5 CVE-2026-3173 The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due … Mitigation only Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-46544 Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-suppl… Mitigation only Fix from $1,6002026-05-27 HIGH 8.8 CVE-2026-46414 Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control … Mitigation only Fix from $1,9502026-05-27 HIGH 8.2 CVE-2026-4868 GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under… GitLab 18.10.7 / 18.11.4+ Fix from $1,9502026-05-27 HIGH 8.8 CVE-2026-38807 Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserController.java component Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-42736 Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows Exploiting Incorrectly Config… Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-42725 Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce all… Mitigation only Fix from $1,6002026-05-27 HIGH 8.2 CVE-2026-8890 code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by su… Patch available Fix from $1,9502026-05-26 MEDIUM 5.9 CVE-2026-44776 Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do not enforce library-level auth… Mitigation only Fix from $1,6002026-05-26