Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2026-24546

Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue af…

Mitigation only
Fix from $1,600 2026-05-25
Mlflow CRITICAL 9.0
CVE-2026-2651

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is …

Fix: after 3.10.1
Fix from $2,300 2026-05-25
Unclassified HIGH 7.3
CVE-2026-9350

A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/app…

Mitigation only
Fix from $1,950 2026-05-24
Unclassified HIGH 8.2
CVE-2026-9284

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing autho…

Mitigation only
Fix from $1,950 2026-05-23
Re305 Firmware HIGH 8.8
CVE-2026-3294

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a l…

Fix: 20260429 / 20260515+
Fix from $1,950 2026-05-22
Kiro Cli HIGH 7.8
CVE-2026-9255

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, includ…

Fix: 1.28.0+
Fix from $1,950 2026-05-22
Unclassified CRITICAL 10.0
CVE-2026-33712

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allo…

Mitigation only
Fix from $2,300 2026-05-22
Devolutions Server MEDIUM 5.4
CVE-2026-9251

Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the admini…

Fix: 2025.3.22.0 / 2026.1.19.0+
Fix from $1,600 2026-05-22
Unclassified MEDIUM 5.3
CVE-2026-8684

The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to th…

Mitigation only
Fix from $1,600 2026-05-22
Unclassified HIGH 7.5
CVE-2026-9011

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi…

Mitigation only
Fix from $1,950 2026-05-22
Unclassified MEDIUM 5.4
CVE-2026-8381

A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not cor…

Mitigation only
Fix from $1,600 2026-05-22
Mu5250 Firmware HIGH 7.5
CVE-2026-44409

There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtai…

Mitigation only
Fix from $1,950 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39831

The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence …

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39833

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign …

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Concrete Cms MEDIUM 5.3
CVE-2026-8239

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-8237

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any convers…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-8238

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversat…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.3
CVE-2026-7879

In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access …

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Unclassified MEDIUM 6.5
CVE-2026-39593

Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects …

Mitigation only
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.3
CVE-2026-27393

Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Security Levels. This issue aff…

Mitigation only
Fix from $1,600 2026-05-21
Unclassified CRITICAL 9.3
CVE-2026-33137

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. I…

Patch available
Fix from $2,300 2026-05-20
Unclassified MEDIUM 6.5
CVE-2026-21836

The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability.  Under certain circumstances, document level access restrictions w…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 5.0
CVE-2026-45443

Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured …

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.5
CVE-2026-27405

Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This iss…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified HIGH 8.8
CVE-2026-5200

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authoriz…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified MEDIUM 5.3
CVE-2025-15369

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec…

Mitigation only
Fix from $1,600 2026-05-20
Date Ical CRITICAL 9.8
CVE-2026-8495

Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.

Fix: 4.0.15+
Fix from $2,300 2026-05-19
Unclassified HIGH 8.1
CVE-2026-34358

CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multip…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified MEDIUM 6.5
CVE-2026-34233

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints w…

Mitigation only
Fix from $1,600 2026-05-19
Unclassified MEDIUM 6.5
CVE-2026-8096

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and…

Mitigation only
Fix from $1,600 2026-05-19