Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.4
CVE-2026-66589

Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue aff…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.7
CVE-2026-53453

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intende…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-12631

The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.7
CVE-2026-71307

Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibl…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-71308

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements ide…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-71317

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent aut…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.9
CVE-2026-67440

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERF…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.2
CVE-2026-67443

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integ…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-47721

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-65959

Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoin…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.1
CVE-2026-67262

Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read fro…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-55106

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-74004

Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions.

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-73994

Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-73404

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-73377

Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-73348

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-73352

Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.2
CVE-2026-73356

Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.6
CVE-2026-69189

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, c…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-66651

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-32549

Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-32472

Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-28567

Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-28571

Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-75846

ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunct…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-75853

ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no au…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-75836

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in M…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-74904

SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockE…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-11801

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is du…

Fix unknown
Fix from $4,900 2026-08-18