Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2026-12406

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authori…

Mitigation only
Fix from $1,600 2026-07-09
Snipe It MEDIUM 6.5
CVE-2026-48492

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorizati…

Fix: 8.6.0+
Fix from $1,600 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-31309

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to…

Patch available
Fix from $2,300 2026-07-08
Unclassified HIGH 8.1
CVE-2026-35552

In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administ…

Mitigation only
Fix from $1,950 2026-07-08
GitLab MEDIUM 5.3
CVE-2026-7492

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under …

Fix: 18.11.7 / 19.0.4+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.5
CVE-2026-59805

Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate…

Patch available
Fix from $1,600 2026-07-08
Unclassified HIGH 7.7
CVE-2026-14373

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This …

Mitigation only
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.5
CVE-2026-59262

AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace member…

Patch available
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.3
CVE-2026-60124

An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persis…

Patch available
Fix from $1,600 2026-07-08
Unclassified HIGH 7.5
CVE-2026-56250

Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbit…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.5
CVE-2026-5356

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions u…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified MEDIUM 5.3
CVE-2026-12097

The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin n…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-12153

The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugi…

Mitigation only
Fix from $2,300 2026-07-08
Coder MEDIUM 5.4
CVE-2026-55432

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `Cre…

Fix: 2.29.17 / 2.32.7+
Fix from $1,600 2026-07-08
Coder MEDIUM 5.4
CVE-2026-55433

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devc…

Fix: 2.29.17 / 2.32.7+
Fix from $1,600 2026-07-08
Unclassified HIGH 7.1
CVE-2026-59704

Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summarie…

Patch available
Fix from $1,950 2026-07-07
Unclassified CRITICAL 9.1
CVE-2026-58473

Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider conf…

Patch available
Fix from $2,300 2026-07-07
Unclassified MEDIUM 6.9
CVE-2026-55417

Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile opti…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified HIGH 8.7
CVE-2026-53730

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @D…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 7.2
CVE-2026-50007

Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared user with user_access on a budg…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 7.5
CVE-2026-59708

The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing una…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 8.3
CVE-2026-11340

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects L…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 8.2
CVE-2026-8377

Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource …

Mitigation only
Fix from $1,950 2026-07-07
Unclassified CRITICAL 9.9
CVE-2026-34048

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket boots…

Patch available
Fix from $2,300 2026-07-07
Unclassified MEDIUM 6.9
CVE-2026-53647

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endp…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified HIGH 8.7
CVE-2026-53643

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unaut…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified MEDIUM 6.5
CVE-2026-34050

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Liv…

Patch available
Fix from $1,600 2026-07-06
Unclassified HIGH 7.8
CVE-2026-6509

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue…

Mitigation only
Fix from $1,950 2026-07-05
Unclassified HIGH 8.2
CVE-2026-27771EPSS 43%

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal…

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 7.5
CVE-2026-25038

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

Patch available
Fix from $1,950 2026-07-03