Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 8.8
CVE-2026-5228

Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly C…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified MEDIUM 6.3
CVE-2026-10815

A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown …

Mitigation only
Fix from $1,600 2026-06-04
Octopus Server MEDIUM 6.5
CVE-2026-4881

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level ch…

Fix: 2025.4.10545 / 2026.1.11313+
Fix from $1,600 2026-06-04
Unclassified HIGH 7.5
CVE-2026-10737

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file functi…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 7.0
CVE-2026-44281

GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user wit…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified HIGH 7.0
CVE-2026-42317

GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete a…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified HIGH 7.0
CVE-2026-42318

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified MEDIUM 5.9
CVE-2026-42320

GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arb…

Mitigation only
Fix from $1,600 2026-06-03
Librechat HIGH 7.1
CVE-2026-31942

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Referenc…

Fix: 0.8.3+
Fix from $1,950 2026-06-02
Unclassified MEDIUM 5.3
CVE-2026-40571

NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wal…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.3
CVE-2026-35443

NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the c…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 6.9
CVE-2026-40314

NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.4
CVE-2026-49782

Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. …

No fix yet
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.4
CVE-2026-27351

Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue …

Mitigation only
Fix from $1,600 2026-06-02
Unclassified HIGH 7.5
CVE-2026-42669

Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventP…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 7.5
CVE-2026-42670

Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Acce…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.8
CVE-2025-53345

Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core. This issue affect…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified MEDIUM 6.5
CVE-2025-52766

Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. Thi…

No fix yet
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.3
CVE-2025-53302

Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constrained by ACLs. This issue affect…

Mitigation only
Fix from $1,600 2026-06-02
Android HIGH 7.8
CVE-2025-26418

In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a manage…

Mitigation only
Fix from $1,950 2026-06-01
Nextcloud Server MEDIUM 6.4
CVE-2026-45285

Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a …

Fix: 32.0.9 / 33.0.3+
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.5
CVE-2026-45267

Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form…

Patch available
Fix from $1,600 2026-06-01
Unclassified HIGH 7.3
CVE-2026-42675

Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue af…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified HIGH 7.5
CVE-2026-42677

Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. Thi…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.5
CVE-2026-42671

Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affect…

No fix yet
Fix from $1,600 2026-06-01
Unclassified CRITICAL 9.1
CVE-2026-42682

Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue aff…

Mitigation only
Fix from $2,300 2026-06-01
Unclassified HIGH 8.8
CVE-2026-40543

SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and ret…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified MEDIUM 5.3
CVE-2026-8382

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due…

Mitigation only
Fix from $1,600 2026-05-31
Youtrack MEDIUM 6.5
CVE-2026-49385

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

Fix: 2026.1.13570+
Fix from $1,600 2026-05-29
Teamcity HIGH 7.6
CVE-2026-49374

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

Fix: 2026.1+
Fix from $1,950 2026-05-29