Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Chrome HIGH 7.5
CVE-2026-8547

Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the re…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Unclassified CRITICAL 9.4
CVE-2026-44592

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone …

Mitigation only
Fix from $2,300 2026-05-14
Unclassified HIGH 7.2
CVE-2026-45371

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated…

Mitigation only
Fix from $1,950 2026-05-14
Mdserver Web CRITICAL 9.8
CVE-2026-41315

mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to…

Fix: after 0.18.4
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.6
CVE-2026-44482

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an…

Mitigation only
Fix from $2,300 2026-05-14
PostgreSQL MEDIUM 5.4
CVE-2026-6472

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, inc…

Fix: 14.23 / 15.18+
Fix from $1,600 2026-05-14
Unclassified HIGH 7.5
CVE-2026-4029

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. Thi…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 8.1
CVE-2026-4030

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and incl…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 7.5
CVE-2026-4031

The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified CRITICAL 9.1
CVE-2026-6512

The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin …

Mitigation only
Fix from $2,300 2026-05-14
Unclassified MEDIUM 5.3
CVE-2026-6145

The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is d…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified CRITICAL 9.8
CVE-2026-6510

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. …

Mitigation only
Fix from $2,300 2026-05-14
Unclassified HIGH 8.8
CVE-2026-6506

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infused…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified MEDIUM 5.4
CVE-2026-3829

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized mod…

Mitigation only
Fix from $1,600 2026-05-14
Erpnext CRITICAL 9.9
CVE-2026-44442

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks…

Fix: 16.9.1+
Fix from $2,300 2026-05-13
Erpnext MEDIUM 6.5
CVE-2026-44448

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper author…

Fix: 15.102.0 / 16.11.0+
Fix from $1,600 2026-05-13
Grafana MEDIUM 6.5
CVE-2026-28380

Any Editor could delete any snapshot, even if they have no access to read or write them.

Fix: 11.6.14 / 12.2.8+
Fix from $1,600 2026-05-13
Prisma Access Agent HIGH 7.8
CVE-2026-0246

A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrati…

Fix: 26.2.1+
Fix from $1,950 2026-05-13
Unclassified HIGH 7.1
CVE-2026-4609

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o…

Mitigation only
Fix from $1,950 2026-05-13
Unclassified MEDIUM 5.3
CVE-2026-2515

The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missi…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified MEDIUM 5.4
CVE-2026-7051

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified MEDIUM 5.3
CVE-2025-14755

The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR) in a…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified HIGH 7.1
CVE-2026-5371

The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access an…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 7.1
CVE-2026-44012

Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and re…

Patch available
Fix from $1,950 2026-05-12
Unclassified HIGH 7.1
CVE-2026-44010

Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elem…

Patch available
Fix from $1,950 2026-05-12
Windows Admin Center HIGH 8.3
CVE-2026-35438

Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 2511+
Fix from $1,950 2026-05-12
Mem0 MEDIUM 5.3
CVE-2026-31245

The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unau…

Mitigation only
Fix from $1,600 2026-05-12
Mem0 MEDIUM 6.5
CVE-2026-31241

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows un…

Mitigation only
Fix from $1,600 2026-05-12
Mem0 CRITICAL 9.1
CVE-2026-31242

The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoin…

Mitigation only
Fix from $2,300 2026-05-12
Mem0 MEDIUM 6.5
CVE-2026-31243

The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DEL…

Mitigation only
Fix from $1,600 2026-05-12