Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2026-30825 hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authentica… Hoppscotch 2026.2.1+ Fix from $1,6002026-03-07 HIGH 7.5 CVE-2026-30230 Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the thumbnail endpoint d… Flare 1.7.2+ Fix from $1,9502026-03-06 MEDIUM 5.3 CVE-2026-30231 Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the raw and direct file … Flare 1.7.2+ Fix from $1,6002026-03-06 MEDIUM 6.5 CVE-2026-30843 Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which cou… Wekan Patch available Fix from $1,6002026-03-06 MEDIUM 6.5 CVE-2026-25877 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1… Chartbrew 4.8.1+ Fix from $1,6002026-03-06 HIGH 7.5 CVE-2026-28469 OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy co… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 MEDIUM 5.4 CVE-2026-27898 Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated r… Vaultwarden 1.35.4+ Fix from $1,6002026-03-04 MEDIUM 5.3 CVE-2026-29069 Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauth… Craft Cms 4.17.0 / 5.9.0+ Fix from $1,6002026-03-04 HIGH 7.5 CVE-2026-28696 Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal ref… Craft Cms 4.17.0 / 5.9.0+ Fix from $1,9502026-03-04 MEDIUM 6.5 CVE-2026-28781 Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the aut… Craft Cms 4.17.0 / 5.9.0+ Fix from $1,6002026-03-04 HIGH 8.4 CVE-2026-0020 In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions … Android Mitigation only Fix from $1,9502026-03-02 MEDIUM 6.3 CVE-2026-28361 NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not validate token ownership, allowing… Nocodb 0.301.3+ Fix from $1,6002026-03-02 HIGH 7.5 CVE-2025-58402 The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter i… Clininet 2025.ms4+ Fix from $1,9502026-03-02 MEDIUM 6.5 CVE-2026-28354 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws,… Clipbucket 5.5.3-59+ Fix from $1,6002026-02-27 MEDIUM 6.5 CVE-2026-27793 Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `GET /api/v1/user/:id` endpoint… Seerr 3.1.0+ Fix from $1,6002026-02-27 HIGH 7.1 CVE-2026-25147 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_pa… Openemr 8.0.0+ Fix from $1,9502026-02-27 MEDIUM 5.3 CVE-2026-1558 The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This i… Mitigation only Fix from $1,6002026-02-27 HIGH 8.3 CVE-2026-28216 hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's perso… Hoppscotch 2026.2.0+ Fix from $1,9502026-02-26 MEDIUM 6.5 CVE-2026-28217 hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection… Hoppscotch 2026.2.0+ Fix from $1,6002026-02-26 MEDIUM 6.5 CVE-2026-28225 Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version… Manyfold 0.133.1+ Fix from $1,6002026-02-26 HIGH 7.5 CVE-2026-27449 Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where c… Mitigation only Fix from $1,9502026-02-26 HIGH 7.5 CVE-2026-26265 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items en… Discourse 2025.12.0 / 2026.1.1+ Fix from $1,9502026-02-26 HIGH 7.5 CVE-2026-26078 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting … Discourse 2025.12.0 / 2026.1.1+ Fix from $1,9502026-02-26 MEDIUM 6.5 CVE-2026-27943 OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the e… Openemr after 8.0.0 Fix from $1,6002026-02-26 MEDIUM 6.5 CVE-2026-25930 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Layout-Based For… Openemr 8.0.0+ Fix from $1,6002026-02-25 HIGH 7.1 CVE-2026-25927 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the DICOM viewer st… Openemr 8.0.0+ Fix from $1,9502026-02-25 MEDIUM 6.5 CVE-2026-25929 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the document control… Openemr 8.0.0+ Fix from $1,6002026-02-25 MEDIUM 6.5 CVE-2026-25220 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Message Center a… Openemr 8.0.0+ Fix from $1,6002026-02-25 MEDIUM 6.5 CVE-2026-27705 Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/as… Plane 1.2.2+ Fix from $1,6002026-02-25 MEDIUM 5.3 CVE-2026-3185 A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the… Sz Boot Parent after 0.9.0 Fix from $1,6002026-02-25