Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 7.5
CVE-2026-66431

Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-66441

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-61978

Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.5
CVE-2026-61984

Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-28186

Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.3
CVE-2026-28188

Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.1
CVE-2026-28173

Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-28181

Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-28159

Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-27999

Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.1
CVE-2026-27535

Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-27345

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.

No fix yet
Fix from $4,900 2026-08-13
PostgreSQL HIGH 7.2
CVE-2026-6471

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-73607

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authori…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.6
CVE-2026-73608

SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authoriz…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-73609

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in t…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.3
CVE-2026-73603

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatfl…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-73605

SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesys…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-14332

The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its…

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-49819

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 5.5
CVE-2026-47718

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.6
CVE-2026-73326

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by …

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72803

SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve blo…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72805

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disc…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72806

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish pass…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72808

SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endp…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72795

SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72796

SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforc…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-72797

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted noteb…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72798

SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation …

No fix yet
Fix from $4,900 2026-08-12