Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.3 CVE-2026-12998 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.5 CVE-2026-13358 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference… No fix yet Fix from $4,0002026-08-16 CRITICAL 9.8 CVE-2026-16142 The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_… No fix yet Fix from $5,7502026-08-15 MEDIUM 5.3 CVE-2026-74242 A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (U… No fix yet Fix from $4,0002026-08-14 HIGH 8.6 CVE-2026-19870 Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding … No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-73841 OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go an… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.4 CVE-2026-73039 streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete othe… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.9 CVE-2026-73656 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/ba… No fix yet Fix from $5,7502026-08-13 MEDIUM 6.5 CVE-2026-72680 Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.8 CVE-2026-72666 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigne… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72657 Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variab… No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-72629 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Prop… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.6 CVE-2026-73644 OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org… No fix yet Fix from $5,7502026-08-13 HIGH 8.1 CVE-2026-72741 Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauth… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.9 CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of … No fix yet Fix from $4,0002026-08-13 MEDIUM 5.4 CVE-2026-58435 Gitea LFS Deploy-Key Privilege Escalation No fix yet Fix from $4,0002026-08-13 MEDIUM 5.9 CVE-2026-57886 Cross-repository issue/comment attachment re-linking can expose private attachment content No fix yet Fix from $4,0002026-08-13 HIGH 8.6 CVE-2026-19734 Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-28155 Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-73616 OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to ot… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.8 CVE-2026-73606 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-prote… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.8 CVE-2026-73610 SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the administrator's entire storage map… No fix yet Fix from $4,0002026-08-13 HIGH 8.1 CVE-2026-73612 File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authentica… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.0 CVE-2026-73488 Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpo… No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-18945 The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling … No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-18750 vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the … No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-18744 Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func on… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.8 CVE-2026-18749 The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefac… No fix yet Fix from $5,7502026-08-12 MEDIUM 5.8 CVE-2026-19130 A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub clust… No fix yet Fix from $4,0002026-08-12 HIGH 8.2 CVE-2026-73303 Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId with… No fix yet Fix from $4,9002026-08-12