Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Fogproject HIGH 8.2
CVE-2026-47688

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES`…

Fix: 1.5.10.1832+
Fix from $1,950 2026-07-21
Unclassified HIGH 7.1
CVE-2026-47657

HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management c…

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.6
CVE-2026-47413

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenan…

Mitigation only
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.6
CVE-2026-47416

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege esc…

No fix yet
Fix from $2,300 2026-07-21
Unclassified MEDIUM 6.5
CVE-2026-47411

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling wo…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 8.1
CVE-2026-47412

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling de…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 8.8
CVE-2026-47405

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization ch…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 8.1
CVE-2026-47409

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling ow…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 8.7
CVE-2026-47394

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original adviso…

No fix yet
Fix from $1,950 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28309

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. Th…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28310

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a sys…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Unclassified MEDIUM 6.5
CVE-2026-65050

Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submi…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 5.0
CVE-2026-11876

In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, al…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.5
CVE-2026-6792

Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. Thi…

No fix yet
Fix from $1,600 2026-07-21
Unclassified CRITICAL 9.6
CVE-2026-65007

The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGen…

No fix yet
Fix from $2,300 2026-07-21
Unclassified MEDIUM 5.3
CVE-2026-8593

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users …

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.5
CVE-2026-13694

The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 7.6
CVE-2026-55544

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write oper…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-55550

NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal appli…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-57494

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated Agent…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.4
CVE-2026-44585

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint acc…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 8.1
CVE-2026-47129

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in …

Mitigation only
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-45295

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/…

No fix yet
Fix from $1,600 2026-07-20
Network Ai MEDIUM 5.9
CVE-2026-58482

Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts…

Fix: 5.12.2+
Fix from $1,600 2026-07-20
Unclassified HIGH 7.5
CVE-2026-64622

Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox …

No fix yet
Fix from $1,950 2026-07-20
Surrealdb MEDIUM 5.4
CVE-2026-63758

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to termi…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63741

SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauth…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-12973

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions ava…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.4
CVE-2026-13432

The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subsc…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-11868

The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also expos…

No fix yet
Fix from $1,600 2026-07-20