Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.6 CVE-2026-46408 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accep… Mitigation only Fix from $1,9502026-05-15 MEDIUM 5.3 CVE-2026-44718 Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, e… Mitigation only Fix from $1,6002026-05-15 HIGH 7.1 CVE-2026-44678 Tuist is a virtual platform team for Swift app devs. In 1.180.8 and earlier, the DELETE /api/projects/{account_handle}/{project_handle}/previews/{pre… Mitigation only Fix from $1,9502026-05-14 HIGH 8.1 CVE-2026-8629 Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, a… Patch available Fix from $1,9502026-05-14 MEDIUM 6.5 CVE-2026-42572 Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a missing authorization direct… Hatchet 0.83.39+ Fix from $1,6002026-05-14 HIGH 8.6 CVE-2026-44504 Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a … Mitigation only Fix from $1,9502026-05-14 HIGH 8.8 CVE-2025-15025 Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry … Mitigation only Fix from $1,9502026-05-14 HIGH 7.1 CVE-2026-5798 Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation … Mitigation only Fix from $1,9502026-05-14 MEDIUM 6.8 CVE-2026-6008 Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Edu… Mitigation only Fix from $1,6002026-05-14 HIGH 8.8 CVE-2025-12008 Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Funct… Mitigation only Fix from $1,9502026-05-14 CRITICAL 9.8 CVE-2026-2347 Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hi… Mitigation only Fix from $2,3002026-05-14 MEDIUM 5.3 CVE-2026-6206 The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from… Patch available Fix from $1,6002026-05-14 HIGH 8.2 CVE-2026-5395 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje… Mitigation only Fix from $1,9502026-05-14 HIGH 8.2 CVE-2026-5396 The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21.… Mitigation only Fix from $1,9502026-05-14 MEDIUM 6.5 CVE-2026-44423 ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any authenticated caller, without … Shellhub 0.24.2+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-44424 ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever the caller is authenticated, wi… Shellhub 0.24.2+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-44426 ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object — including the members list (u… Shellhub 0.24.2+ Fix from $1,6002026-05-13 HIGH 8.1 CVE-2026-42463 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure … Sqlbot 1.8.0+ Fix from $1,9502026-05-13 MEDIUM 5.3 CVE-2026-6965 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and inc… Mitigation only Fix from $1,6002026-05-13 MEDIUM 5.3 CVE-2025-14033 The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the… Mitigation only Fix from $1,6002026-05-13 MEDIUM 5.3 CVE-2026-44341 GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job detai… Mitigation only Fix from $1,6002026-05-12 CRITICAL 9.1 CVE-2026-42889 Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebS… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-29204 Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without a… Mitigation only Fix from $2,3002026-05-12 MEDIUM 5.4 CVE-2023-30059 An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the ch… Mitigation only Fix from $1,6002026-05-12 HIGH 8.8 CVE-2026-6001 Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This i… Mitigation only Fix from $1,9502026-05-12 HIGH 7.7 CVE-2026-43890 Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API endpoint in server/routes/api/su… Mitigation only Fix from $1,9502026-05-11 HIGH 8.1 CVE-2026-38568 HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /inte… Mitigation only Fix from $1,9502026-05-11 HIGH 7.7 CVE-2026-33356 In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and rece… Mitigation only Fix from $1,9502026-05-11 HIGH 8.1 CVE-2026-42609 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with o… Grav after 1.8.0 Fix from $1,9502026-05-11 MEDIUM 6.8 CVE-2026-42291 SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoints for reading and creating s… Mitigation only Fix from $1,6002026-05-08