Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2026-12723

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overw…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-16215

A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Ha…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-16197

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/…

No fix yet
Fix from $1,600 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16123

A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the fi…

No fix yet
Fix from $1,600 2026-07-18
Unclassified CRITICAL 9.6
CVE-2026-55518

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_…

Patch available
Fix from $2,300 2026-07-17
Unclassified HIGH 7.1
CVE-2026-45704

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization bet…

Patch available
Fix from $1,950 2026-07-17
Unclassified HIGH 8.1
CVE-2026-45260

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE op…

Patch available
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.4
CVE-2026-45703

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportB…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-48014

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{trans…

Patch available
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-48008

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to fu…

Patch available
Fix from $1,600 2026-07-17
Unclassified CRITICAL 9.1
CVE-2026-12694

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This…

No fix yet
Fix from $2,300 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-63100

Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify glo…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-15783

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any reposito…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 8.5
CVE-2026-12715

Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other user…

Mitigation only
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-16017

A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the compo…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.5
CVE-2026-11575

The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used …

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 7.5
CVE-2026-13765

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all …

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-8616

The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing n…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-62235

Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.4
CVE-2026-62232

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user e…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 8.8
CVE-2026-62233

grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.user…

No fix yet
Fix from $1,950 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62218

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers …

Fix: 2026.5.27+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62207

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attacke…

Fix: 2026.6.5+
Fix from $1,950 2026-07-17
Openclaw HIGH 7.1
CVE-2026-62205

OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the af…

Fix: 2026.6.6+
Fix from $1,950 2026-07-17
Openclaw HIGH 7.1
CVE-2026-62206

OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust ca…

Fix: 2026.6.9+
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-45334

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature returned lock information withou…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.0
CVE-2026-44176

Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft re…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.4
CVE-2026-61718

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware autho…

Patch available
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-46515

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pin…

Patch available
Fix from $2,300 2026-07-16
Unclassified MEDIUM 5.4
CVE-2026-63082

Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers…

No fix yet
Fix from $1,600 2026-07-16