Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.1 CVE-2026-40896 OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas` permission in any project ca… Openproject 17.3.0+ Fix from $1,9502026-04-20 MEDIUM 6.3 CVE-2026-6613 A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_schedule/get_schedule_data of … Mitigation only Fix from $1,6002026-04-20 MEDIUM 6.3 CVE-2026-6614 A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_pr… Mitigation only Fix from $1,6002026-04-20 MEDIUM 6.3 CVE-2026-6612 A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_execution/update_agent_execution of t… Mitigation only Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-6584 A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_user of the file superagi/contr… Mitigation only Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-6585 A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/… Mitigation only Fix from $1,6002026-04-20 MEDIUM 6.3 CVE-2026-6586 A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/co… Mitigation only Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-6583 A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14. This affects the function delete_api_key/edit_api_key of the file superag… Mitigation only Fix from $1,6002026-04-19 MEDIUM 6.3 CVE-2026-6571 A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/co… Mitigation only Fix from $1,6002026-04-19 HIGH 7.1 CVE-2026-40480 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person re… Patch available Fix from $1,9502026-04-18 MEDIUM 5.3 CVE-2026-5234 The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability e… Mitigation only Fix from $1,6002026-04-17 HIGH 8.1 CVE-2026-3605 An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or… Vault 1.19.16 / 1.20.10+ Fix from $1,9502026-04-17 HIGH 8.8 CVE-2026-40308 My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJAX endpoint, registered for un… Mitigation only Fix from $1,9502026-04-16 MEDIUM 5.3 CVE-2026-4160 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje… Mitigation only Fix from $1,6002026-04-16 HIGH 8.1 CVE-2026-40784 Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Config… Mitigation only Fix from $1,9502026-04-15 MEDIUM 5.3 CVE-2026-40737 Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exploiting Incorrectly Configure… No fix yet Fix from $1,6002026-04-15 HIGH 8.8 CVE-2026-5617 The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_r… Mitigation only Fix from $1,9502026-04-15 MEDIUM 5.4 CVE-2026-34213 Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.71.0, improper authorization i… Docmost 0.71.0+ Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2026-34370 Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Ref… Chamilo Lms after 1.11.38 Fix from $1,6002026-04-14 HIGH 7.1 CVE-2026-34602 Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecu… Chamilo Lms after 1.11.38 Fix from $1,9502026-04-14 HIGH 8.8 CVE-2026-38529 A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to… Krayin Crm No fix yet Fix from $1,9502026-04-14 HIGH 8.1 CVE-2026-38530 A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated atta… Krayin Crm No fix yet Fix from $1,9502026-04-14 HIGH 8.1 CVE-2026-38532 A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated att… Krayin Crm No fix yet Fix from $1,9502026-04-14 MEDIUM 5.3 CVE-2025-13822 MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an un… Mcphub 0.11.0+ Fix from $1,6002026-04-14 HIGH 8.8 CVE-2026-25654 A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when proces… Mitigation only Fix from $1,9502026-04-14 MEDIUM 5.4 CVE-2026-33740 EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contai… Espocrm 9.3.4+ Fix from $1,6002026-04-13 MEDIUM 6.5 CVE-2026-40043 Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low-privilege users to escalate … Mitigation only Fix from $1,6002026-04-13 HIGH 8.1 CVE-2026-40252 FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access… Fastgpt 4.14.10.4+ Fix from $1,9502026-04-10 MEDIUM 6.5 CVE-2026-33736 Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can enumerate all platform users an… Chamilo Lms Patch available Fix from $1,6002026-04-10 HIGH 7.1 CVE-2026-33702 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Object Reference (IDOR) vulnera… Chamilo Lms 1.11.38+ Fix from $1,9502026-04-10