Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2026-33158 Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, … Craft Cms 4.17.8 / 5.9.14+ Fix from $1,6002026-03-24 HIGH 8.1 CVE-2026-33678 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`W… Vikunja 2.2.1+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-33484EPSS 6% Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{… Langflow 1.9.0+ Fix from $1,9502026-03-24 HIGH 8.1 CVE-2026-32300 Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi… Connect Cms 1.41.1 / 2.41.1+ Fix from $1,9502026-03-23 MEDIUM 6.5 CVE-2026-23487 Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.detail Endpoint Leaks the Superad… Blinko 1.8.4+ Fix from $1,6002026-03-23 MEDIUM 5.3 CVE-2026-23488 Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an unauthorized access vulnerabilit… Blinko 1.8.4+ Fix from $1,6002026-03-23 MEDIUM 6.5 CVE-2026-30886 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure… New Api 0.11.4+ Fix from $1,6002026-03-23 CRITICAL 9.1 CVE-2026-33297 WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administr… Avideo 26.0+ Fix from $2,3002026-03-23 MEDIUM 5.3 CVE-2026-33425 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenticated users can determine whe… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-21 HIGH 8.8 CVE-2026-33053 Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accept… Langflow 1.9.0+ Fix from $1,9502026-03-20 MEDIUM 6.5 CVE-2026-32761 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6… Filebrowser 2.62.0+ Fix from $1,6002026-03-20 HIGH 8.1 CVE-2026-29189 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the Sui… Suitecrm 7.15.1 / 8.9.3+ Fix from $1,9502026-03-20 MEDIUM 6.5 CVE-2026-32697 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, the `RecordHandler… Suitecrm 8.9.3+ Fix from $1,6002026-03-20 MEDIUM 6.5 CVE-2026-32039 OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers t… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-33304 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in… Openemr 8.0.0.2+ Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-25744 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API a… Openemr 8.0.0.2+ Fix from $1,6002026-03-19 CRITICAL 9.8 CVE-2026-32867 OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files vi… Ecase Ecomplaint 10.1.0.0+ Fix from $2,3002026-03-19 MEDIUM 6.5 CVE-2025-32223 Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Sec… Mitigation only Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-27397 Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro allows Exploiting Incorrectly… Mitigation only Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-25745 OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the m… Openemr after 8.0.0 Fix from $1,6002026-03-18 MEDIUM 6.6 CVE-2026-32694 In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a … Juju 3.6.19+ Fix from $1,6002026-03-18 CRITICAL 9.6 CVE-2026-30884 mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. P… Patch available Fix from $2,3002026-03-18 MEDIUM 6.5 CVE-2026-26004 Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object… Sentry 26.1.0+ Fix from $1,6002026-03-18 HIGH 8.8 CVE-2026-24901 Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the doc… Outline 1.4.0+ Fix from $1,9502026-03-17 HIGH 8.8 CVE-2026-4208 The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login at… Mfa Mail 1.0.7+ Fix from $1,9502026-03-17 MEDIUM 5.3 CVE-2025-69727 An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (index.js and composeUrlImgPho… Mitigation only Fix from $1,6002026-03-16 MEDIUM 6.3 CVE-2026-4171 A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of t… Mitigation only Fix from $1,6002026-03-16 HIGH 8.6 CVE-2026-3020 Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user account, such as changing th… Mitigation only Fix from $1,9502026-03-16 HIGH 7.5 CVE-2026-1947 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… Mitigation only Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2017-20223 Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass… Sdt Cs3b1 Firmware Mitigation only Fix from $2,3002026-03-16