Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Discourse MEDIUM 5.3
CVE-2026-34154

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the dis…

Fix: 2026.1.4 / 2026.3.1+
Fix from $1,600 2026-05-19
Unclassified HIGH 7.5
CVE-2026-47100

Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows …

Mitigation only
Fix from $1,950 2026-05-19
Unclassified HIGH 7.1
CVE-2026-30950

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.…

Patch available
Fix from $1,950 2026-05-18
Summarize MEDIUM 5.4
CVE-2026-45244

Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call…

Fix: 0.15.1+
Fix from $1,600 2026-05-18
Summarize HIGH 7.1
CVE-2026-45242

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write fil…

Fix: 0.15.1+
Fix from $1,950 2026-05-18
Summarize MEDIUM 6.1
CVE-2026-45243

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages …

Fix: 0.15.1+
Fix from $1,600 2026-05-18
Mattermost Server MEDIUM 6.5
CVE-2026-5163

Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated att…

Fix: 11.5.2+
Fix from $1,600 2026-05-18
Mattermost Server MEDIUM 6.5
CVE-2026-3117

Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin whic…

Fix: after 11.3.4
Fix from $1,600 2026-05-18
Unclassified MEDIUM 5.4
CVE-2026-1631

The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Fe…

Mitigation only
Fix from $1,600 2026-05-18
Unclassified MEDIUM 5.3
CVE-2026-8681

The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the…

Mitigation only
Fix from $1,600 2026-05-16
Open Webui MEDIUM 6.5
CVE-2026-45667

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, GET /api/v1/memories/ef is accessi…

Fix: 0.8.0+
Fix from $1,600 2026-05-15
Open Webui HIGH 7.1
CVE-2026-45350

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.6, there is a vulnerability in chat c…

Fix: 0.8.6+
Fix from $1,950 2026-05-15
Open Webui HIGH 7.1
CVE-2026-44569

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, there's an IDOR in the channels m…

Fix: 0.6.19+
Fix from $1,950 2026-05-15
Open Webui MEDIUM 6.5
CVE-2026-44571

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.6, in standard channels (i.e., channe…

Fix: 0.8.6+
Fix from $1,600 2026-05-15
Open Webui HIGH 7.2
CVE-2026-45395

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the tool update endpoint (POST /ap…

Fix: 0.9.5+
Fix from $1,950 2026-05-15
Open Webui MEDIUM 5.4
CVE-2026-44563

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /api/generate, /api/embed, /ap…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui HIGH 7.1
CVE-2026-45399

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user with low pr…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 7.1
CVE-2026-44556

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the Ope…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui MEDIUM 5.4
CVE-2026-44558

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the channel router does not call f…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui MEDIUM 6.5
CVE-2026-44560

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the type: "file" (non-full-context…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui MEDIUM 6.5
CVE-2026-44562

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import end…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui MEDIUM 5.0
CVE-2026-44550

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = Con…

Fix: 0.9.0+
Fix from $1,600 2026-05-15
Open Webui HIGH 8.1
CVE-2026-44554

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/retrieval/process…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Open Webui HIGH 7.6
CVE-2026-44555

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI supports model composit…

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Unclassified MEDIUM 5.4
CVE-2026-46365

phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authentic…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified MEDIUM 5.3
CVE-2026-44718

Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, e…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified MEDIUM 5.3
CVE-2026-44719

Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, collaborators.list,…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified CRITICAL 10.0
CVE-2026-2031

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remo…

Mitigation only
Fix from $2,300 2026-05-15
Unclassified MEDIUM 6.5
CVE-2026-4683

The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ro…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified HIGH 8.1
CVE-2026-4094

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability che…

Mitigation only
Fix from $1,950 2026-05-15