Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Powershell Universal MEDIUM 5.0
CVE-2026-16799

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticat…

Fix: 2026.2.3.0+
Fix from $1,600 2026-07-24
Unclassified HIGH 7.3
CVE-2026-10033

The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the p…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 5.3
CVE-2026-12654

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. Th…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.4
CVE-2026-12689

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions,…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.3
CVE-2026-11354

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the …

No fix yet
Fix from $1,600 2026-07-24
Azure Dns CRITICAL 9.8
CVE-2026-58275

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Unclassified CRITICAL 9.9
CVE-2026-47724

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trust…

Mitigation only
Fix from $2,300 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-47755

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged auth…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 8.1
CVE-2026-65916

CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows aut…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 8.5
CVE-2026-65895

Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users w…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65525

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65529

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65499

Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2026-65500

Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65506

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65489

Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2026-65495

Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.3
CVE-2026-65484

Contributor Broken Access Control in Style Kits <= 2.6.5 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65485

Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65486

Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65487

Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65476

Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-65478

Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-65479

Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65468

Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65469

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65472

Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.

No fix yet
Fix from $1,600 2026-07-23
Intellij Idea HIGH 8.6
CVE-2026-64814

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

Fix: 2026.2+
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65452

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65453

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

No fix yet
Fix from $1,600 2026-07-23