Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 8.6
CVE-2026-55638

9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /co…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 7.2
CVE-2026-1667

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, a…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-61441

PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either…

Patch available
Fix from $1,600 2026-07-10
Teamcity HIGH 8.1
CVE-2026-59796

In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks

Fix: 2026.1.2+
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-56279

Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despit…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-11990

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15332

A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of t…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 7.5
CVE-2026-15291

The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 8.0
CVE-2026-15293

The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.5
CVE-2026-44918

OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-11818

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-15320

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pi…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-59853

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria fr…

Patch available
Fix from $1,600 2026-07-09
Discourse MEDIUM 6.5
CVE-2026-46413

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart u…

Fix: 2026.1.5 / 2026.4.2+
Fix from $1,600 2026-07-09
Junos MEDIUM 5.5
CVE-2026-33802

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-o…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.3
CVE-2026-54004

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenti…

Patch available
Fix from $1,600 2026-07-09
Unclassified HIGH 7.1
CVE-2026-54005

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowe…

Patch available
Fix from $1,950 2026-07-09
Pipecat MEDIUM 6.5
CVE-2026-54695

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development…

Fix: 1.4.0+
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-49274

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access …

Patch available
Fix from $1,600 2026-07-09
Open Webui MEDIUM 5.4
CVE-2026-59227

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required on…

Fix: 0.10.0+
Fix from $1,600 2026-07-09
Open Webui MEDIUM 6.3
CVE-2026-59225

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user with…

Fix: 0.10.0+
Fix from $1,600 2026-07-09
Open Webui CRITICAL 9.0
CVE-2026-59216

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and ex…

Fix: 0.10.0+
Fix from $2,300 2026-07-09
Unclassified HIGH 8.7
CVE-2026-12593

The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for crea…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-9028

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. Thi…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-9021

The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin regi…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-12428

The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values()…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-7558

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and in…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.2
CVE-2026-8848

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorizatio…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-8996

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Mitigation only
Fix from $1,600 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-14245

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Acc…

Mitigation only
Fix from $2,300 2026-07-09