Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.8 CVE-2016-20033 Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing … Streaming Engine No fix yet Fix from $1,9502026-03-16 HIGH 8.8 CVE-2026-3999 A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability only impacts specific confi… Id Server 9.0.0+ Fix from $1,9502026-03-13 MEDIUM 5.4 CVE-2026-2879 The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.2. This is due to missi… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.3 CVE-2026-2888 The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, … Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.4 CVE-2026-2257 The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.2 due to missing valida… Mitigation only Fix from $1,6002026-03-13 CRITICAL 9.9 CVE-2026-27591 Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS al… Winter 1.0.477 / 1.1.12+ Fix from $2,3002026-03-11 HIGH 7.7 CVE-2026-32131 ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, whi… Zitadel 3.4.8 / 4.12.2+ Fix from $1,9502026-03-11 HIGH 7.2 CVE-2026-32103 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studiocms_api/dashboard/create-reset… Studiocms 0.4.3+ Fix from $1,9502026-03-11 MEDIUM 5.4 CVE-2026-32104 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the updateUserNotifications endpoint accepts a… Studiocms 0.4.3+ Fix from $1,6002026-03-11 HIGH 8.8 CVE-2026-32097 PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticated user may be able to retrie… Pingpong 7.27.2+ Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2019-25487EPSS 8% SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands b… Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31874 Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly… Taskosaur Patch available Fix from $2,3002026-03-11 HIGH 8.1 CVE-2025-67298 An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile Classroomio 0.2.6+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-1992 The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2.… Mitigation only Fix from $1,9502026-03-11 MEDIUM 5.4 CVE-2026-2917 The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 vi… Mitigation only Fix from $1,6002026-03-11 MEDIUM 6.4 CVE-2026-2918 The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 vi… Mitigation only Fix from $1,6002026-03-11 MEDIUM 6.8 CVE-2026-1753 The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbit… Mitigation only Fix from $1,6002026-03-11 HIGH 8.1 CVE-2026-3453 The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to… Mitigation only Fix from $1,9502026-03-11 MEDIUM 5.4 CVE-2026-31832 Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability exists in a backoffice API endp… Umbraco Cms 16.5.1 / 17.2.2+ Fix from $1,6002026-03-10 MEDIUM 6.5 CVE-2026-31820 Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulnerability exists in multiple sh… Sylius 2.0.16 / 2.1.12+ Fix from $1,6002026-03-10 MEDIUM 5.0 CVE-2026-30959 OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a… Oneuptime 10.0.21+ Fix from $1,6002026-03-10 CRITICAL 9.1 CVE-2026-30969 Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1… Coral Server 1.1.0+ Fix from $2,3002026-03-10 HIGH 8.8 CVE-2026-30944 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoi… Studiocms 0.4.0+ Fix from $1,9502026-03-10 HIGH 7.1 CVE-2026-30945 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens… Studiocms 0.4.0+ Fix from $1,9502026-03-10 HIGH 8.6 CVE-2026-30920 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled sta… Oneuptime 10.0.19+ Fix from $1,9502026-03-10 MEDIUM 5.4 CVE-2026-30927 Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any u… Admidio 5.0.6+ Fix from $1,6002026-03-10 MEDIUM 5.3 CVE-2026-30885 WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user with… Avideo 25.0+ Fix from $1,6002026-03-10 HIGH 7.5 CVE-2025-62166 FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is … Freshrss 1.28.0+ Fix from $1,9502026-03-09 MEDIUM 5.3 CVE-2026-30857 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authoriza… Weknora 0.3.0+ Fix from $1,6002026-03-07 HIGH 8.8 CVE-2026-30823 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, lea… Flowise 3.0.13+ Fix from $1,9502026-03-07