Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Enterprise Server MEDIUM 6.5
CVE-2026-9132

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private …

Fix: 3.17.17 / 3.18.11+
Fix from $1,600 2026-06-30
Unclassified HIGH 8.1
CVE-2026-58377

JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, up…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified MEDIUM 6.5
CVE-2026-58176

RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without an…

Patch available
Fix from $1,600 2026-06-30
Unclassified HIGH 8.8
CVE-2026-58165

OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fi…

Patch available
Fix from $1,950 2026-06-30
Unclassified MEDIUM 6.5
CVE-2026-58167

Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-…

Patch available
Fix from $1,600 2026-06-30
Unclassified HIGH 8.8
CVE-2026-58168

DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due t…

Patch available
Fix from $1,950 2026-06-30
Activemq HIGH 7.5
CVE-2026-54475

Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations …

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Unclassified MEDIUM 5.3
CVE-2026-12349

The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified CRITICAL 9.6
CVE-2026-57498

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controller…

Mitigation only
Fix from $2,300 2026-06-29
Mythic MEDIUM 6.5
CVE-2026-57952

Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rule…

Fix: 3.4.0.60+
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-57949

ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-…

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-57339

Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.

Mitigation only
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-57340

Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.

Mitigation only
Fix from $1,600 2026-06-29
Unclassified HIGH 7.1
CVE-2026-57332

Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-57334

Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

No fix yet
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-57335

Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.

Mitigation only
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.3
CVE-2026-57327

Subscriber Broken Access Control in MainWP <= 6.1.1 versions.

Mitigation only
Fix from $1,600 2026-06-29
Unclassified HIGH 8.3
CVE-2025-2902

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform…

Mitigation only
Fix from $1,950 2026-06-29
Mlflow HIGH 8.8
CVE-2026-13484

A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component…

Fix: after 2026-05-26
Fix from $1,950 2026-06-28
Unclassified MEDIUM 5.3
CVE-2026-12432

The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_faile…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.5
CVE-2026-3462

The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'pro…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 5.3
CVE-2026-12404

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …

Mitigation only
Fix from $1,600 2026-06-27
Budibase CRITICAL 9.4
CVE-2026-50137

Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-so…

Fix: 3.39.0+
Fix from $2,300 2026-06-26
Unclassified HIGH 8.2
CVE-2026-55188

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bu…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.7
CVE-2026-55189

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read an…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.6
CVE-2026-49991

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket …

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-47193

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical …

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-44734

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenPr…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 8.8
CVE-2026-57518

Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate…

Mitigation only
Fix from $1,950 2026-06-26
Lxd CRITICAL 9.6
CVE-2026-12411

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gu…

Fix: 6.9+
Fix from $2,300 2026-06-26