Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.5 CVE-2026-65523 Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-28180 Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions. No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-14313 PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-wooco… No fix yet Fix from $1,6002026-08-06 HIGH 7.1 CVE-2026-9130 IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access … Langflow 1.11.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-48912 Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar… Answer 2.0.2+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-71251 Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth mid… No fix yet Fix from $1,6002026-08-05 HIGH 8.3 CVE-2026-71242 Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePol… No fix yet Fix from $1,9502026-08-05 HIGH 8.3 CVE-2026-55739 Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->compan… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-11454 The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up… No fix yet Fix from $1,6002026-08-05 MEDIUM 5.3 CVE-2026-16981 The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or owne… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.3 CVE-2026-18818 A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views… No fix yet Fix from $1,6002026-08-04 HIGH 8.3 CVE-2026-70476 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in pa… No fix yet Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-69258 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/… No fix yet Fix from $1,9502026-08-04 HIGH 8.5 CVE-2026-69250 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/… No fix yet Fix from $1,9502026-08-04 MEDIUM 6.3 CVE-2026-18722 A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.3 CVE-2026-18631 A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/sr… No fix yet Fix from $1,6002026-08-03 CRITICAL 9.8 CVE-2026-2346 Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affe… No fix yet Fix from $2,3002026-08-03 MEDIUM 6.5 CVE-2026-68582 Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1… No fix yet Fix from $1,6002026-08-02 HIGH 7.1 CVE-2025-71400 better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows auth… No fix yet Fix from $1,9502026-08-02 CRITICAL 9.8 CVE-2026-67342 ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoi… No fix yet Fix from $2,3002026-08-01 HIGH 7.1 CVE-2026-67329 @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscri… No fix yet Fix from $1,9502026-08-01 HIGH 8.3 CVE-2026-67331 better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authentic… No fix yet Fix from $1,9502026-08-01 MEDIUM 5.3 CVE-2025-14073 The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in … No fix yet Fix from $1,6002026-08-01 HIGH 7.1 CVE-2026-65981 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH reque… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.6 CVE-2026-17349 /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones th… Pgadmin 4 9.17+ Fix from $2,3002026-07-31 MEDIUM 5.3 CVE-2026-17567 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.4 CVE-2026-8155 The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated … No fix yet Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-15209 The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-14843 The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an un… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.4 CVE-2026-12697 The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messag… No fix yet Fix from $1,6002026-07-31