Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.3 CVE-2026-72802 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths… No fix yet Fix from $4,0002026-08-12 HIGH 8.5 CVE-2026-19228 GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could… No fix yet Fix from $4,9002026-08-12 HIGH 8.7 CVE-2026-73298 The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for m… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-73239 Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache All… Allura No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-68076 Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to p… Airflow 3.3.1+ Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-47230 Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same ro… No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-47231 Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking tha… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-47227 Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-47226 Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-16737 The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identif… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.4 CVE-2026-64927 A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the syst… No fix yet Fix from $4,0002026-08-12 HIGH 7.7 CVE-2026-66878 A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subs… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.9 CVE-2026-48765 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from… No fix yet Fix from $5,7502026-08-11 MEDIUM 5.4 CVE-2026-19579 Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The ca… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-69117 NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitr… No fix yet Fix from $4,0002026-08-11 HIGH 8.3 CVE-2026-69119 Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or pe… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-48494 TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook … No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-58650 Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Visual Studio Code No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-47704 TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook ses… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.9 CVE-2026-73068 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, th… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-56721 CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authentic… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-72774 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access… No fix yet Fix from $4,9002026-08-11 HIGH 7.2 CVE-2026-72763 n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-72546 An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to inject attendees an… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-72547 An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to bulk import attende… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-72543 An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any con… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-72545 An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any con… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-19424 Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a sp… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-18620 A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServic… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.9 CVE-2026-72876 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getA… No fix yet Fix from $5,7502026-08-10