Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 8.2
CVE-2026-73658

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() a…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-73305

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking app…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.9
CVE-2026-73656

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/ba…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.1
CVE-2026-72675

Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPE…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72681

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates …

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.1
CVE-2026-72665

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Acce…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.6
CVE-2026-72669

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update …

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72661

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72664

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functi…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.1
CVE-2026-59714

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite …

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.4
CVE-2026-73653

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 5.9
CVE-2026-58432

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-58433

Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.5
CVE-2026-58434

Private Repository Metadata Remains Accessible After Access Revocation

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-58438

Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.9
CVE-2026-57886

Cross-repository issue/comment attachment re-linking can expose private attachment content

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-73349

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-73353

Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-73401

Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-73403

Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.3
CVE-2026-66689

Unauthenticated Broken Access Control in Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-66693

Subscriber Broken Access Control in Motors <= 1.4.113 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-66660

Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.5
CVE-2026-66469

Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-66461

Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-66464

Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.5
CVE-2026-66466

Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= …

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-66454

Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.0
CVE-2026-66455

Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-66459

Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.

No fix yet
Fix from $4,000 2026-08-13