Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified CRITICAL 9.1
CVE-2026-3141

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/re…

No fix yet
Fix from $2,300 2026-08-01
Unclassified MEDIUM 5.4
CVE-2026-45086

Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin…

No fix yet
Fix from $1,600 2026-07-31
Pgadmin 4 MEDIUM 5.4
CVE-2026-17350

The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consist…

Fix: 9.17+
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-15227

Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" per…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-18436

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore RES…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-18437

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability c…

No fix yet
Fix from $1,600 2026-07-31
Build Of Keycloak MEDIUM 5.4
CVE-2026-18218

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a spe…

No fix yet
Fix from $1,600 2026-07-31
Build Of Keycloak MEDIUM 6.5
CVE-2026-18208

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access manageme…

No fix yet
Fix from $1,600 2026-07-31
Build Of Keycloak HIGH 8.1
CVE-2026-18214

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was fo…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-14930

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allo…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-14317

The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.6
CVE-2026-67527

OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and al…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.2
CVE-2026-15397

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is du…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.4
CVE-2026-15252

The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authentic…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-11867

The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and d…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.5
CVE-2026-12500

The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress …

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 8.8
CVE-2026-14356

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin …

Mitigation only
Fix from $1,950 2026-07-30
Unclassified HIGH 7.1
CVE-2026-16543

Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-w…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.1
CVE-2026-15228

Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-66724

MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoi…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.0
CVE-2026-66723

MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-4604

The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_…

No fix yet
Fix from $1,600 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-14488

The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission exten…

No fix yet
Fix from $2,300 2026-07-29
Atlas HIGH 8.8
CVE-2026-50622

Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated …

Fix: 2.6.0+
Fix from $1,950 2026-07-29
Build Of Keycloak MEDIUM 5.5
CVE-2026-18201

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator w…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-13692

The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.5
CVE-2026-54719

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?…

No fix yet
Fix from $1,950 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-16184

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Unclassified HIGH 8.8
CVE-2026-49258

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-oper…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.4
CVE-2026-66751

Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server …

No fix yet
Fix from $1,600 2026-07-28