Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2026-43934 e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized … Patch available Fix from $1,6002026-05-26 MEDIUM 5.3 CVE-2026-40127 OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated use… Mitigation only Fix from $1,6002026-05-25 HIGH 8.8 CVE-2026-35430 Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges ov… Azure Privileged Identity Management Mitigation only Fix from $1,9502026-05-22 HIGH 7.1 CVE-2026-39968 TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution … Patch available Fix from $1,9502026-05-22 MEDIUM 6.5 CVE-2026-28444 Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId … Patch available Fix from $1,6002026-05-22 HIGH 7.1 CVE-2026-3473 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, whi… Mattermost Server 10.11.15 / 11.4.5+ Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-8679 The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the h… Patch available Fix from $1,9502026-05-22 MEDIUM 5.3 CVE-2026-8337 Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public an… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 MEDIUM 5.3 CVE-2026-8204 Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosu… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 HIGH 8.8 CVE-2026-47101 LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generat… Litellm 1.83.14+ Fix from $1,9502026-05-21 HIGH 7.5 CVE-2025-13479 Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Truste… Mitigation only Fix from $1,9502026-05-21 HIGH 8.1 CVE-2026-45760 (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K… Mitigation only Fix from $1,9502026-05-21 CRITICAL 10.0 CVE-2026-9152 A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiri… Mitigation only Fix from $2,3002026-05-21 MEDIUM 6.5 CVE-2026-9136 A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request dat… Misp 2.5.38+ Fix from $1,6002026-05-20 HIGH 8.1 CVE-2026-9087 A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identit… Build Of Keycloak Mitigation only Fix from $1,9502026-05-20 MEDIUM 6.5 CVE-2026-6072 The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all vers… Mitigation only Fix from $1,6002026-05-20 HIGH 8.8 CVE-2026-42097 Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only … Pro Cloud Server after 6.1.167 Fix from $1,9502026-05-19 MEDIUM 6.8 CVE-2026-4630 A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Ser… Build Of Keycloak 26.4.12+ Fix from $1,6002026-05-19 MEDIUM 6.9 CVE-2026-46721 The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignm… Mitigation only Fix from $1,6002026-05-19 MEDIUM 5.3 CVE-2026-33052 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add… Patch available Fix from $1,6002026-05-19 HIGH 7.5 CVE-2026-41949 Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up … Dify after 1.14.1 Fix from $1,9502026-05-18 CRITICAL 9.1 CVE-2026-41947EPSS 6% Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configuratio… Dify after 1.14.1 Fix from $2,3002026-05-18 MEDIUM 6.3 CVE-2026-8786 A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file i… Weknora after 0.3.6 Fix from $1,6002026-05-18 MEDIUM 6.5 CVE-2026-45666 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the API /api/v1/notes/{note_id} e… Open Webui 0.8.11+ Fix from $1,6002026-05-15 HIGH 8.3 CVE-2026-44570 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, authorization controls surroundin… Open Webui 0.6.19+ Fix from $1,9502026-05-15 HIGH 8.1 CVE-2026-45402 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multiple endpoints accept a user-s… Open Webui 0.9.5+ Fix from $1,9502026-05-15 HIGH 7.5 CVE-2026-45398 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() chec… Open Webui 0.9.5+ Fix from $1,9502026-05-15 HIGH 8.0 CVE-2026-45671 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permane… Open Webui 0.9.0+ Fix from $1,9502026-05-15 HIGH 7.1 CVE-2026-45349 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a user just needs to use the API e… Open Webui 0.9.0+ Fix from $1,9502026-05-15 HIGH 8.1 CVE-2026-46407 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-toke… Mitigation only Fix from $1,9502026-05-15