Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2026-33703 Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/per… Chamilo Lms Mitigation only Fix from $1,6002026-04-10 HIGH 7.1 CVE-2026-32894 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebo… Chamilo Lms 1.11.38+ Fix from $1,9502026-04-10 HIGH 7.1 CVE-2026-32930 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebo… Chamilo Lms 1.11.38+ Fix from $1,9502026-04-10 MEDIUM 6.5 CVE-2026-33141 Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endp… Chamilo Lms after 1.11.38 Fix from $1,6002026-04-10 HIGH 7.2 CVE-2026-29002 CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with th… Couchcms after 2.4 Fix from $1,9502026-04-10 HIGH 8.8 CVE-2026-39942 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-cont… Directus 11.17.0+ Fix from $1,9502026-04-09 HIGH 7.3 CVE-2026-5842 A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the compo… Mitigation only Fix from $1,9502026-04-09 HIGH 8.1 CVE-2026-35478 InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token a… Inventree after 1.2.6 Fix from $1,9502026-04-08 MEDIUM 6.5 CVE-2026-34985 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging … Loris after 27.0.2 Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-35165 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging … Loris after 27.0.2 Fix from $1,6002026-04-08 HIGH 7.4 CVE-2026-32589 A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can inter… Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,9502026-04-08 MEDIUM 5.3 CVE-2026-39616 Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Co… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-39526 Authorization Bypass Through User-Controlled Key vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control … Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-4654 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, a… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-5167 The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Cont… Mitigation only Fix from $1,6002026-04-08 HIGH 7.7 CVE-2026-39374 Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modi… Plane 1.3.0+ Fix from $1,9502026-04-07 MEDIUM 6.5 CVE-2026-39354 Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoold allows any logged-in, low-… Scoold 1.66.2+ Fix from $1,6002026-04-07 HIGH 8.1 CVE-2026-39331 ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper a… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 7.6 CVE-2026-39384 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_… Freescout 1.8.212+ Fix from $1,9502026-04-07 MEDIUM 6.5 CVE-2026-35584 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation_id}/… Freescout 1.8.212+ Fix from $1,6002026-04-07 HIGH 7.3 CVE-2026-35489 Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping… Recipes 2.6.4+ Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-5465 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up t… Mitigation only Fix from $1,9502026-04-07 MEDIUM 5.4 CVE-2026-35183 Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion featur… Bravecms 2.0.6+ Fix from $1,6002026-04-06 MEDIUM 6.5 CVE-2026-35173 Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authentica… Chyrp Lite 2026.01+ Fix from $1,6002026-04-06 HIGH 8.1 CVE-2026-35045 Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update… Recipes 2.6.4+ Fix from $1,9502026-04-06 CRITICAL 10.0 CVE-2026-34444 Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are acc… Lupa after 2.6 Fix from $2,3002026-04-06 HIGH 8.1 CVE-2026-4896 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direc… Mitigation only Fix from $1,9502026-04-04 HIGH 8.1 CVE-2026-25197 A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call. Cloud Api 2.12.2026+ Fix from $1,9502026-04-03 MEDIUM 6.5 CVE-2026-34832 Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback … Scoold 1.66.1+ Fix from $1,6002026-04-02 MEDIUM 5.4 CVE-2026-34584 listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission check… Listmonk 6.1.0+ Fix from $1,6002026-04-02