Vulnerability index

Browse CVEs

1,748 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.6 CVE-2025-71388 stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that ch… No fix yet Fix from $1,9502026-07-16 HIGH 8.2 CVE-2026-35147 HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication s… Dfx Server after 2.5 Fix from $1,9502026-07-16 MEDIUM 5.9 CVE-2026-12510 The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, al… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.3 CVE-2026-15909 A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the fil… No fix yet Fix from $1,6002026-07-16 HIGH 8.5 CVE-2026-55234 Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.j… Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.5 CVE-2026-53447 Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoard… Mitigation only Fix from $1,6002026-07-15 CRITICAL 9.9 CVE-2026-54052 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with… N8n Mcp 2.56.1+ Fix from $2,3002026-07-15 HIGH 7.1 CVE-2026-52869 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streama… Mcp Python Sdk 1.27.2+ Fix from $1,9502026-07-15 HIGH 8.1 CVE-2026-58660 Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the c… Mitigation only Fix from $1,9502026-07-15 HIGH 7.7 CVE-2026-48799 Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provi… Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.5 CVE-2025-32781 Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does… Mitigation only Fix from $1,6002026-07-15 CRITICAL 9.9 CVE-2026-44986 Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from … Mitigation only Fix from $2,3002026-07-15 HIGH 8.6 CVE-2026-61836 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key der… Directus 12.0.0+ Fix from $1,9502026-07-15 MEDIUM 6.9 CVE-2026-59236 Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prosper… Mitigation only Fix from $1,6002026-07-15 MEDIUM 6.3 CVE-2026-59254 n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outsi… Mitigation only Fix from $1,6002026-07-15 MEDIUM 6.5 CVE-2026-59259 n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between… N8n 1.123.61 / 2.27.4+ Fix from $1,6002026-07-15 HIGH 8.7 CVE-2026-59235 Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /ap… Mitigation only Fix from $1,9502026-07-15 MEDIUM 5.5 CVE-2026-11580 The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-dupli… Mitigation only Fix from $1,6002026-07-15 HIGH 8.8 CVE-2026-59733 Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --… Rclone 1.74.4+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-15637 Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated lo… Devolutions Server 2026.1.23.0 / 2026.2.12.0+ Fix from $1,9502026-07-14 MEDIUM 6.9 CVE-2026-52837 Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/r… Mitigation only Fix from $1,6002026-07-14 HIGH 8.7 CVE-2026-15389 A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time web application and its REST… Mitigation only Fix from $1,9502026-07-14 MEDIUM 5.3 CVE-2026-15622 A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace… Patch available Fix from $1,6002026-07-14 HIGH 7.1 CVE-2026-58410 ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which al… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-57694 Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Sec… Mitigation only Fix from $1,6002026-07-13 HIGH 7.5 CVE-2026-14165 An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker … Mitigation only Fix from $1,9502026-07-13 MEDIUM 5.6 CVE-2026-15516 A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php … Mitigation only Fix from $1,6002026-07-13 HIGH 7.1 CVE-2026-55880 OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the owners… Mitigation only Fix from $1,9502026-07-10 HIGH 7.1 CVE-2026-55881 OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session'… Patch available Fix from $1,9502026-07-10 MEDIUM 5.0 CVE-2026-55515 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and dele… Snipe It 8.6.2+ Fix from $1,6002026-07-10