Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2026-25440

Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.3
CVE-2025-68049

Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.5
CVE-2025-69332

Subscriber Broken Access Control in Bookify <= 1.1.1 versions.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38329

Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.p…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified HIGH 7.1
CVE-2026-5230

Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Con…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 6.5
CVE-2026-48969

Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.5
CVE-2025-64215

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issu…

Mitigation only
Fix from $1,600 2026-06-15
Unclassified HIGH 8.6
CVE-2026-34024

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. A…

Mitigation only
Fix from $1,950 2026-06-15
Openclaw MEDIUM 6.6
CVE-2026-53820

OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated call…

Fix: 2026.5.12+
Fix from $1,600 2026-06-12
Openclaw HIGH 8.8
CVE-2026-53821

OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization …

Fix: 2026.5.18+
Fix from $1,950 2026-06-12
Unclassified HIGH 7.1
CVE-2026-47120

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified HIGH 7.1
CVE-2026-48119

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authent…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified CRITICAL 9.9
CVE-2026-46716

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem…

Mitigation only
Fix from $2,300 2026-06-12
Discourse MEDIUM 5.3
CVE-2026-45085

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l…

Fix: 2026.1.0 / 2026.1.4+
Fix from $1,600 2026-06-12
Kitty HIGH 7.8
CVE-2026-42851

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a d…

Fix: 0.47.0+
Fix from $1,950 2026-06-12
Unclassified HIGH 7.5
CVE-2026-50108

The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the l…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-50244

The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account …

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.1
CVE-2026-10715

Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user…

Patch available
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-50026

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unau…

Mitigation only
Fix from $1,600 2026-06-12
Cloud Production Api MEDIUM 6.5
CVE-2026-50084

The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an inst…

No fix yet
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-44975

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users i…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified HIGH 8.1
CVE-2026-7368

The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credent…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified HIGH 7.2
CVE-2026-47197

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can use the bot to moderate user…

Mitigation only
Fix from $1,950 2026-06-12
Openclaw MEDIUM 6.6
CVE-2026-53818

OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only…

Fix: 2026.4.24+
Fix from $1,600 2026-06-11
Openclaw MEDIUM 6.5
CVE-2026-53815

OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust cal…

Fix: 2026.5.19+
Fix from $1,600 2026-06-11
Openclaw HIGH 7.2
CVE-2026-53816

OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec …

Fix: 2026.5.18+
Fix from $1,950 2026-06-11
Unclassified HIGH 7.2
CVE-2026-47163

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any guild member who can invoke sl…

Mitigation only
Fix from $1,950 2026-06-11
Unclassified CRITICAL 9.4
CVE-2026-4764

A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user wit…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified MEDIUM 5.4
CVE-2023-25969

Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control S…

Mitigation only
Fix from $1,600 2026-06-11
Unclassified MEDIUM 5.4
CVE-2022-45813

Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels…

Mitigation only
Fix from $1,600 2026-06-11