Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-66105

Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Contr…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified MEDIUM 5.3
CVE-2026-25436

Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This …

Mitigation only
Fix from $1,600 2026-05-07
Unclassified MEDIUM 6.5
CVE-2026-6214

The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_fo…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified MEDIUM 6.5
CVE-2026-41658

Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces authorization for destructive opera…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified MEDIUM 6.5
CVE-2026-4807

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to…

No fix yet
Fix from $1,600 2026-05-07
Unclassified MEDIUM 5.3
CVE-2026-6222

The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processR…

Mitigation only
Fix from $1,600 2026-05-07
Openclaw MEDIUM 6.5
CVE-2026-43583

OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media replay. Attackers can exploit r…

Fix: 2026.4.14+
Fix from $1,600 2026-05-06
Openclaw CRITICAL 9.8
CVE-2026-43575

OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactiv…

Fix: 2026.4.10+
Fix from $2,300 2026-05-06
Openclaw MEDIUM 6.5
CVE-2026-43577

OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through browser act/evaluate interactions.…

Fix: 2026.4.9+
Fix from $1,600 2026-05-06
Openclaw MEDIUM 6.5
CVE-2026-43579

OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that allows operators with write …

Fix: 2026.4.10+
Fix from $1,600 2026-05-06
Openclaw HIGH 7.7
CVE-2026-43580

OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF pol…

Fix: 2026.4.10+
Fix from $1,950 2026-05-06
Unclassified MEDIUM 6.5
CVE-2026-5753

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. T…

Mitigation only
Fix from $1,600 2026-05-06
Unclassified MEDIUM 5.3
CVE-2026-3208

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Mitigation only
Fix from $1,600 2026-05-06
Vaultwarden MEDIUM 5.3
CVE-2026-33420

Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organ…

Fix: 1.35.5+
Fix from $1,600 2026-05-05
Openclaw MEDIUM 5.3
CVE-2026-43572

OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to ap…

Fix: 2026.4.14+
Fix from $1,600 2026-05-05
Openclaw HIGH 7.7
CVE-2026-43573

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attacker…

Fix: 2026.4.10+
Fix from $1,950 2026-05-05
Openclaw MEDIUM 6.5
CVE-2026-43567

OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesyst…

Fix: 2026.4.10+
Fix from $1,600 2026-05-05
Openclaw MEDIUM 6.5
CVE-2026-43568

OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory …

Fix: 2026.4.10+
Fix from $1,600 2026-05-05
Unclassified HIGH 7.7
CVE-2026-42436

OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab routes that fail to consistently…

Patch available
Fix from $1,950 2026-05-05
Openclaw HIGH 8.5
CVE-2026-42439

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Atta…

Fix: 2026.4.10+
Fix from $1,950 2026-05-05
Unclassified MEDIUM 6.5
CVE-2026-42433

OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persiste…

Patch available
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.5
CVE-2026-4362

The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `Li…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified CRITICAL 9.8
CVE-2026-5294

The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route…

Mitigation only
Fix from $2,300 2026-05-05
N8n HIGH 7.5
CVE-2026-42226

n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify wheth…

Fix: 1.123.33 / 2.17.5+
Fix from $1,950 2026-05-04
N8n MEDIUM 6.5
CVE-2026-42228

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Tri…

Fix: 1.123.32 / 2.17.4+
Fix from $1,600 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42809

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Unclassified HIGH 7.1
CVE-2026-4100

The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versio…

Patch available
Fix from $1,950 2026-05-02
Unclassified MEDIUM 5.3
CVE-2026-4024

The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 5.3
CVE-2026-4650

The FundPress – WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and including 2.0.8. This is due to m…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified HIGH 8.8
CVE-2026-6963

The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX …

Mitigation only
Fix from $1,950 2026-05-02