Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2026-57400

Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorr…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.5
CVE-2026-57390

Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Expl…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.5
CVE-2026-57392

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.5
CVE-2026-57375

Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.5
CVE-2026-57377

Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 7.5
CVE-2026-57378

Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Leve…

Mitigation only
Fix from $1,950 2026-07-13
Mattermost Server MEDIUM 5.4
CVE-2026-10085

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private…

Fix: 10.11.20 / 11.6.5+
Fix from $1,600 2026-07-13
Helix Ultimate CRITICAL 9.1
CVE-2026-57830

Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulner…

Fix: after 2.2.6
Fix from $2,300 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15541

A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of…

Patch available
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15507

A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the compone…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified HIGH 7.1
CVE-2026-61442

PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents,…

Patch available
Fix from $1,950 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-9017

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-12994

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. …

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-6803

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-6804

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12.…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-13250

The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin no…

Mitigation only
Fix from $1,600 2026-07-11
Flowdrop MEDIUM 5.4
CVE-2026-58589

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

Fix: after 1.6.0
Fix from $1,600 2026-07-10
Flowdrop MEDIUM 5.4
CVE-2026-58590

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

Fix: 1.6.0+
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-47422

Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and t…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-48127

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through…

Patch available
Fix from $1,600 2026-07-10
Unclassified HIGH 7.1
CVE-2026-49394

Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace becau…

Patch available
Fix from $1,950 2026-07-10
Wisski MEDIUM 6.5
CVE-2026-13239

Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from 0.0.0 to 4.2.0.

Fix: 4.2+
Fix from $1,600 2026-07-10
Paragraphs MEDIUM 6.5
CVE-2026-13240

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.

Fix: 1.21+
Fix from $1,600 2026-07-10
Paragraphs MEDIUM 6.5
CVE-2026-13241

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.

Fix: 1.21+
Fix from $1,600 2026-07-10
Localgov Workflows CRITICAL 9.8
CVE-2026-10768

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0…

Fix: 1.6.0+
Fix from $2,300 2026-07-10
Rabbitmq Server MEDIUM 5.0
CVE-2026-57221

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive …

Fix: 4.2.6+
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-13039

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.3
CVE-2026-57850

RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTran…

Patch available
Fix from $1,950 2026-07-10
Snipe It HIGH 7.7
CVE-2026-54329

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory m…

Fix: 8.6.2+
Fix from $1,950 2026-07-10
Unclassified HIGH 8.1
CVE-2026-56668

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-typ…

Patch available
Fix from $1,950 2026-07-10