Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 8.8 CVE-2026-42205 Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in th… Mitigation only Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-44400 MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers … Mailenable 10.56+ Fix from $2,3002026-05-08 MEDIUM 5.8 CVE-2026-42279 solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API accepts a… Solidtime Patch available Fix from $1,6002026-05-08 MEDIUM 6.5 CVE-2026-42277 Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to… Onyx 3.0.9 / 3.1.6+ Fix from $1,6002026-05-08 HIGH 8.8 CVE-2026-42278 UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a crit… Patch available Fix from $1,9502026-05-08 HIGH 7.1 CVE-2026-41906 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hide… Mitigation only Fix from $1,9502026-05-07 MEDIUM 5.3 CVE-2026-27329 Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Cont… No fix yet Fix from $1,6002026-05-07 HIGH 7.5 CVE-2026-40981 When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially expos… Spring Cloud Config 3.1.14 / 4.1.10+ Fix from $1,9502026-05-07 MEDIUM 5.4 CVE-2026-20219 A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of other users … Mitigation only Fix from $1,6002026-05-06 HIGH 7.7 CVE-2026-7573 An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-p… Velociraptor 0.76.5+ Fix from $1,9502026-05-06 MEDIUM 6.5 CVE-2026-41950 Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded… Dify 1.14.0+ Fix from $1,6002026-05-05 MEDIUM 6.5 CVE-2026-3454 The GenerateBlocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.0. This is due to… Mitigation only Fix from $1,6002026-05-05 MEDIUM 5.3 CVE-2026-2729 The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not… Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.3 CVE-2026-7782 A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Cli… Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.5 CVE-2026-42227 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped… N8n 1.123.32 / 2.17.4+ Fix from $1,6002026-05-04 HIGH 7.5 CVE-2026-41471 The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerability in the QR code scanning end… Mitigation only Fix from $1,9502026-05-04 CRITICAL 9.9 CVE-2026-29200 A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows … Mitigation only Fix from $2,3002026-05-04 MEDIUM 5.3 CVE-2026-7702 A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the file /workspace/:workspaceId… No fix yet Fix from $1,6002026-05-03 MEDIUM 6.5 CVE-2026-5337 During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Obj… Mitigation only Fix from $1,6002026-05-03 MEDIUM 6.5 CVE-2026-7681 A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an unknown functionality of the … Mitigation only Fix from $1,6002026-05-03 HIGH 8.1 CVE-2026-2554 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direc… Mitigation only Fix from $1,9502026-05-02 HIGH 8.1 CVE-2026-7491 School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific p… Mitigation only Fix from $1,9502026-05-02 MEDIUM 5.3 CVE-2026-7638 The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi… Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.3 CVE-2026-7510 A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark… Patch available Fix from $1,6002026-04-30 HIGH 8.1 CVE-2026-6542 IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users… Langflow 1.9.0+ Fix from $1,9502026-04-30 MEDIUM 5.4 CVE-2026-7502 A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/… Patch available Fix from $1,6002026-04-30 HIGH 7.5 CVE-2026-4503 IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference… Langflow Desktop after 1.8.4 Fix from $1,9502026-04-30 HIGH 8.1 CVE-2026-40600 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Char… Mitigation only Fix from $1,9502026-04-30 HIGH 8.1 CVE-2026-7399 Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects P… Mitigation only Fix from $1,9502026-04-30 HIGH 7.1 CVE-2026-42515 This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vul… Mitigation only Fix from $1,9502026-04-29