Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.5 CVE-2026-68500 Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_lo… No fix yet Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-68501 Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_loc… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-10700 IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access … Langflow 1.9.0+ Fix from $1,6002026-07-30 HIGH 7.1 CVE-2026-12945 IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on … Langflow 1.10.2+ Fix from $1,9502026-07-30 HIGH 8.1 CVE-2026-15658 A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of o… No fix yet Fix from $1,9502026-07-30 HIGH 8.1 CVE-2026-67348 Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read anot… No fix yet Fix from $1,9502026-07-30 MEDIUM 5.3 CVE-2026-15255 The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the ident… No fix yet Fix from $1,6002026-07-30 MEDIUM 5.3 CVE-2026-15257 The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing ac… No fix yet Fix from $1,6002026-07-30 MEDIUM 5.4 CVE-2026-14310 The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning o… No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-13178 The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauth… No fix yet Fix from $1,9502026-07-30 MEDIUM 5.3 CVE-2026-13345 The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCom… No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2025-60931 An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attacker… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.5 CVE-2026-5060 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all… No fix yet Fix from $1,6002026-07-29 MEDIUM 5.4 CVE-2026-14224 The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the… No fix yet Fix from $1,6002026-07-29 HIGH 8.8 CVE-2026-57510 SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated user… No fix yet Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-49258 Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-oper… No fix yet Fix from $1,9502026-07-28 MEDIUM 6.9 CVE-2026-59240 The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notifi… No fix yet Fix from $1,6002026-07-27 MEDIUM 5.4 CVE-2026-48052 Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organizatio… No fix yet Fix from $1,6002026-07-27 MEDIUM 5.0 CVE-2026-17531 A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/route… No fix yet Fix from $1,6002026-07-27 HIGH 7.5 CVE-2026-59539 Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. No fix yet Fix from $1,9502026-07-27 HIGH 7.4 CVE-2026-59546 Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. No fix yet Fix from $1,9502026-07-27 HIGH 7.7 CVE-2026-17527 In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, include… No fix yet Fix from $1,9502026-07-27 MEDIUM 6.5 CVE-2026-66412 Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are… No fix yet Fix from $1,6002026-07-27 CRITICAL 9.3 CVE-2026-66013 OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to upd… No fix yet Fix from $2,3002026-07-25 HIGH 8.1 CVE-2026-65708 sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account fi… No fix yet Fix from $1,9502026-07-24 HIGH 8.3 CVE-2026-65709 sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enume… No fix yet Fix from $1,9502026-07-24 HIGH 7.1 CVE-2026-65710 sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag… No fix yet Fix from $1,9502026-07-24 MEDIUM 6.5 CVE-2026-17059 A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access managem… Build Of Keycloak No fix yet Fix from $1,6002026-07-24 MEDIUM 5.3 CVE-2026-13464 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version… No fix yet Fix from $1,6002026-07-24 CRITICAL 9.9 CVE-2026-15630 A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a… No fix yet Fix from $2,3002026-07-23