Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Librechat MEDIUM 6.5
CVE-2026-54027

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authen…

Fix: after 0.8.3
Fix from $1,600 2026-06-25
Librechat MEDIUM 6.5
CVE-2026-54029

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId e…

Fix: after 0.8.3
Fix from $1,600 2026-06-25
K2 MEDIUM 6.5
CVE-2026-48941

The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` c…

Fix: after 2.26
Fix from $1,600 2026-06-25
Unclassified MEDIUM 6.5
CVE-2026-57619

Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 6.5
CVE-2026-57429

Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.4
CVE-2026-56023

Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

Mitigation only
Fix from $1,600 2026-06-25
Unclassified HIGH 8.1
CVE-2026-54842

Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue a…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.5
CVE-2026-54844

Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.5
CVE-2026-54830

Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.5
CVE-2026-54828

Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.5
CVE-2026-27366

Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.

Mitigation only
Fix from $1,950 2026-06-25
GitLab MEDIUM 5.3
CVE-2026-2238

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under…

Fix: 18.11.6 / 19.0.3+
Fix from $1,600 2026-06-25
Unclassified HIGH 8.1
CVE-2026-55762

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, th…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.1
CVE-2026-52812

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS-root>/<oid[0]>/<oid[1]>/<oid…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 7.5
CVE-2026-52799

Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.7
CVE-2026-45677

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.1
CVE-2026-27708

FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method ac…

Mitigation only
Fix from $1,950 2026-06-24
Assembla MEDIUM 5.4
CVE-2026-57304

A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifi…

Fix: after 1.4
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.4
CVE-2026-57291

Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an att…

Mitigation only
Fix from $1,600 2026-06-24
Ec2 Fleet MEDIUM 5.4
CVE-2026-57294

A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect …

Fix: after 4.2.3.539.v8fedff2a_81c3
Fix from $1,600 2026-06-24
Unclassified HIGH 8.8
CVE-2026-7761

The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.1…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-9175

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.5
CVE-2026-9178

The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-8690

The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-9172

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due t…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 8.8
CVE-2026-4297

The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is du…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-7617

The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin no…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-8617

The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is …

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-12094

The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified CRITICAL 9.6
CVE-2026-11807

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not v…

Mitigation only
Fix from $2,300 2026-06-23