Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 8.7 CVE-2026-47743 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive da… No fix yet Fix from $1,9502026-07-23 MEDIUM 6.5 CVE-2026-47755 ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged auth… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-65696 Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenti… No fix yet Fix from $1,6002026-07-23 HIGH 8.8 CVE-2026-65917 CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's … No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-65501 Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-65463 Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-61946 Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-3482 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could… Sterling B2b Integrator after 6.2.2.0_1 Fix from $1,6002026-07-22 CRITICAL 9.6 CVE-2026-16624 Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated tea… No fix yet Fix from $2,3002026-07-22 HIGH 8.8 CVE-2026-65013 Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to acc… No fix yet Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-65016 n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provi… N8n 1.123.64 / 2.29.8+ Fix from $1,9502026-07-22 MEDIUM 6.5 CVE-2026-2406 Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration an… No fix yet Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-65316 XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from j… No fix yet Fix from $1,6002026-07-21 MEDIUM 5.4 CVE-2026-61064 Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supported versions that are affec… Irecruitment after 12.2.15 Fix from $1,6002026-07-21 HIGH 7.1 CVE-2026-56147 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity co… Kibana 8.19.18 / 9.3.7+ Fix from $1,9502026-07-21 HIGH 7.6 CVE-2026-47414 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference… No fix yet Fix from $1,9502026-07-21 HIGH 8.3 CVE-2026-47415 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference… No fix yet Fix from $1,9502026-07-21 HIGH 8.1 CVE-2026-47417 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference… Mitigation only Fix from $1,9502026-07-21 HIGH 8.1 CVE-2026-47418 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference… No fix yet Fix from $1,9502026-07-21 HIGH 8.3 CVE-2026-47419 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Referenc… No fix yet Fix from $1,9502026-07-21 HIGH 8.1 CVE-2026-47406 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference… No fix yet Fix from $1,9502026-07-21 CRITICAL 9.4 CVE-2026-47407 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources un… No fix yet Fix from $2,3002026-07-21 MEDIUM 6.5 CVE-2026-47408 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference… No fix yet Fix from $1,6002026-07-21 HIGH 8.8 CVE-2026-47399 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain… Mitigation only Fix from $1,9502026-07-21 MEDIUM 6.5 CVE-2026-15342 Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or… No fix yet Fix from $1,6002026-07-21 CRITICAL 9.1 CVE-2026-28317 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires … Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28313 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary accoun… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28314 SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28316 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administr… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28305 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain ac… Serv U 2026.3+ Fix from $2,3002026-07-21