Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2026-69114 Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers t… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.9 CVE-2026-72863 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au… No fix yet Fix from $5,7502026-08-10 MEDIUM 5.3 CVE-2026-68870 The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-ag… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.5 CVE-2026-68871 The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic loo… Apache Airflow Providers Apache Yandex No fix yet Fix from $4,0002026-08-10 MEDIUM 6.5 CVE-2026-68872 The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variabl… Apache Airflow Providers Amazon No fix yet Fix from $4,0002026-08-10 CRITICAL 9.6 CVE-2026-72737 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs … No fix yet Fix from $5,7502026-08-10 HIGH 8.4 CVE-2026-72734 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/… No fix yet Fix from $4,9002026-08-10 HIGH 8.6 CVE-2026-19433 Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated us… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-72689 A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read com… No fix yet Fix from $4,9002026-08-10 HIGH 7.1 CVE-2026-72690 An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory su… No fix yet Fix from $4,9002026-08-10 HIGH 8.7 CVE-2026-59233 Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.6 CVE-2026-72564 An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in … No fix yet Fix from $5,7502026-08-10 MEDIUM 6.5 CVE-2026-19077 The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing an… No fix yet Fix from $4,0002026-08-10 MEDIUM 5.4 CVE-2026-15238 The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticat… No fix yet Fix from $4,0002026-08-10 MEDIUM 5.4 CVE-2026-16574 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belong… No fix yet Fix from $1,6002026-08-08 HIGH 8.8 CVE-2026-48169 PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break wo… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.5 CVE-2026-70561 TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege gues… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2026-66058 Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is poss… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.5 CVE-2026-16039 The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated us… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.5 CVE-2026-70557 diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those … No fix yet Fix from $1,6002026-08-06 CRITICAL 9.9 CVE-2026-67622 Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attac… No fix yet Fix from $2,3002026-08-06 MEDIUM 6.5 CVE-2026-64662 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view con… No fix yet Fix from $1,6002026-08-06 HIGH 8.5 CVE-2026-45414 Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to th… No fix yet Fix from $1,9502026-08-06 HIGH 8.1 CVE-2026-19111 Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-14842 The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauth… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-15147 The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to v… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-13399 The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unau… No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-10599 The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order bein… No fix yet Fix from $1,9502026-08-06 HIGH 8.8 CVE-2026-18258 Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows … Escriptorium No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-18275 Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to… Escriptorium No fix yet Fix from $1,6002026-08-06