Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2026-47745

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and…

Patch available
Fix from $1,600 2026-05-29
Intellij Idea HIGH 8.8
CVE-2026-49367

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

Fix: 2026.1.1+
Fix from $1,950 2026-05-29
Unclassified HIGH 8.1
CVE-2026-47740

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were call…

Patch available
Fix from $1,950 2026-05-29
Unclassified MEDIUM 6.5
CVE-2026-47742

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping…

Patch available
Fix from $1,600 2026-05-29
Unclassified HIGH 8.8
CVE-2026-47125

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/varia…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45632

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. …

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45625

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endp…

Mitigation only
Fix from $2,300 2026-05-29
Openclaw HIGH 8.0
CVE-2026-35630

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver i…

Fix: 2026.5.18+
Fix from $1,950 2026-05-29
Openclaw HIGH 8.3
CVE-2026-32905

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat sende…

Fix: 2026.5.4+
Fix from $1,950 2026-05-29
Unclassified HIGH 7.5
CVE-2018-25391

HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sendi…

No fix yet
Fix from $1,950 2026-05-29
Unclassified CRITICAL 9.1
CVE-2026-4290

The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoin…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified MEDIUM 5.3
CVE-2025-12714

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check…

Mitigation only
Fix from $1,600 2026-05-29
Portainer MEDIUM 6.5
CVE-2026-44884

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…

Fix: 2.33.8 / 2.39.1+
Fix from $1,600 2026-05-28
Portainer HIGH 8.8
CVE-2026-44848

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…

Fix: 2.33.8 / 2.39.2+
Fix from $1,950 2026-05-28
Portainer HIGH 8.8
CVE-2026-44849

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…

Fix: 2.33.8 / 2.39.1+
Fix from $1,950 2026-05-28
Unclassified HIGH 7.2
CVE-2026-42071

Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility fun…

Patch available
Fix from $1,950 2026-05-28
Nautobot MEDIUM 5.4
CVE-2026-44794

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericF…

Fix: 2.4.33 / 3.1.2+
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.3
CVE-2026-6937

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all ver…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.3
CVE-2026-7552

The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin no…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified HIGH 8.8
CVE-2026-7802

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 8.8
CVE-2026-46414

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control …

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-48151

Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generi…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified CRITICAL 9.9
CVE-2026-46425

Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCI…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified HIGH 8.8
CVE-2026-45717

Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/…

Mitigation only
Fix from $1,950 2026-05-27
Free5gc CRITICAL 9.4
CVE-2026-44326

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound …

Fix: 4.2.2+
Fix from $2,300 2026-05-27
Free5gc CRITICAL 10.0
CVE-2026-44327

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2…

Fix: 4.2.2+
Fix from $2,300 2026-05-27
Free5gc HIGH 8.2
CVE-2026-44328

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound …

Fix: 4.2.2+
Fix from $1,950 2026-05-27
Free5gc CRITICAL 10.0
CVE-2026-44329

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/b…

Fix: 4.2.2+
Fix from $2,300 2026-05-27
Free5gc HIGH 7.3
CVE-2026-44320

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound O…

Fix: 4.2.2+
Fix from $1,950 2026-05-27
Free5gc HIGH 7.5
CVE-2026-44321

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound …

Fix: 4.2.2+
Fix from $1,950 2026-05-27