Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.1 CVE-2026-42516 This vulnerability exists in e-Sushrut due to improper authorization checks during resource access. An authenticated attacker could exploit this vuln… Mitigation only Fix from $1,9502026-04-29 HIGH 7.1 CVE-2026-42517 This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could ex… Mitigation only Fix from $1,9502026-04-29 HIGH 7.7 CVE-2026-41649 Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.… Outline 1.7.0+ Fix from $1,9502026-04-28 MEDIUM 5.4 CVE-2026-41406 OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can … Openclaw 2026.3.31+ Fix from $1,6002026-04-28 CRITICAL 9.8 CVE-2026-24178 NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause author… Nvflare 2.7.2+ Fix from $2,3002026-04-28 MEDIUM 5.8 CVE-2026-41372 OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. … Openclaw 2026.4.2+ Fix from $1,6002026-04-28 HIGH 7.1 CVE-2026-28747 A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed. Mitigation only Fix from $1,9502026-04-27 MEDIUM 5.4 CVE-2026-7145 A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/Workspa… Mitigation only Fix from $1,6002026-04-27 MEDIUM 5.3 CVE-2025-15626 Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application No fix yet Fix from $1,6002026-04-27 MEDIUM 5.3 CVE-2026-6810 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63… Mitigation only Fix from $1,6002026-04-24 MEDIUM 5.3 CVE-2026-2028 The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi… Patch available Fix from $1,6002026-04-24 HIGH 8.7 CVE-2026-6375 A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PN… Mitigation only Fix from $1,9502026-04-23 HIGH 8.8 CVE-2026-41277 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the Docum… Flowise 3.1.0+ Fix from $1,9502026-04-23 HIGH 7.5 CVE-2026-41279 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST… Flowise 3.1.0+ Fix from $1,9502026-04-23 CRITICAL 9.8 CVE-2026-41267 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2018-25270 ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functi… Thinkphp 5.0.23+ Fix from $2,3002026-04-22 HIGH 7.6 CVE-2026-5750 An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated users to access data belonging … Mitigation only Fix from $1,9502026-04-22 MEDIUM 6.5 CVE-2026-6355 A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insec… Augmentt 2025-10-02+ Fix from $1,6002026-04-22 MEDIUM 6.5 CVE-2026-41127 BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite capt… Mitigation only Fix from $1,6002026-04-22 CRITICAL 9.6 CVE-2026-5845 An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attac… Enterprise Server 3.14.26 / 3.15.21+ Fix from $2,3002026-04-21 MEDIUM 6.5 CVE-2026-40907 WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an In… Avideo after 29.0 Fix from $1,6002026-04-21 HIGH 7.1 CVE-2026-40865 Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document vie… Mitigation only Fix from $1,9502026-04-21 HIGH 8.6 CVE-2026-40866 Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upl… Mitigation only Fix from $1,9502026-04-21 HIGH 7.1 CVE-2026-40867 Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment… Mitigation only Fix from $1,9502026-04-21 CRITICAL 9.0 CVE-2026-5652 An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform … Crafty Controller 4.10.4+ Fix from $2,3002026-04-21 HIGH 7.6 CVE-2026-40589 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an… Patch available Fix from $1,9502026-04-21 HIGH 7.1 CVE-2026-40591 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-control… Patch available Fix from $1,9502026-04-21 MEDIUM 5.7 CVE-2026-40570 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` … Patch available Fix from $1,6002026-04-21 HIGH 8.8 CVE-2026-39386 Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticat… Neko 3.0.11 / 3.1.2+ Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2025-66954 A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid usernames an… Mitigation only Fix from $1,6002026-04-20