Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Deskflow HIGH 7.8
CVE-2026-41477

Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with …

Fix: after 1.26.0.161
Fix from $1,950 2026-04-24
Unclassified MEDIUM 5.3
CVE-2026-3569

The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-pr…

Mitigation only
Fix from $1,600 2026-04-24
Unclassified MEDIUM 5.3
CVE-2026-5347

The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of…

Mitigation only
Fix from $1,600 2026-04-24
Unclassified MEDIUM 5.3
CVE-2026-5488

The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and includi…

Mitigation only
Fix from $1,600 2026-04-24
Actual HIGH 8.8
CVE-2026-33318

Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on se…

Fix: 26.4.0+
Fix from $1,950 2026-04-24
X3500 Firmware HIGH 8.1
CVE-2026-40623

A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without suff…

Mitigation only
Fix from $1,950 2026-04-24
Openclaw HIGH 8.8
CVE-2026-41352

OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mec…

Fix: 2026.3.31+
Fix from $1,950 2026-04-23
Openclaw HIGH 8.8
CVE-2026-41349

OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patc…

Fix: 2026.3.28+
Fix from $1,950 2026-04-23
Flowise HIGH 7.5
CVE-2026-41266

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes …

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Unclassified HIGH 7.2
CVE-2026-5464

The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugi…

Mitigation only
Fix from $1,950 2026-04-23
Paperclipai CRITICAL 10.0
CVE-2026-41679

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated a…

Fix: 2026.416.0+
Fix from $2,300 2026-04-23
Unclassified HIGH 8.3
CVE-2026-41454

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to per…

Patch available
Fix from $1,950 2026-04-22
Rustfs HIGH 8.3
CVE-2026-40937

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src…

Mitigation only
Fix from $1,950 2026-04-22
Unclassified CRITICAL 9.8
CVE-2026-6235

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up …

Mitigation only
Fix from $2,300 2026-04-22
Unclassified MEDIUM 5.3
CVE-2026-4117

The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is due to a missing capability c…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified CRITICAL 9.1
CVE-2026-4119

The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin…

Mitigation only
Fix from $2,300 2026-04-22
Unclassified MEDIUM 6.5
CVE-2026-6834

The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database conten…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 5.3
CVE-2026-41128

Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `vie…

Patch available
Fix from $1,600 2026-04-22
Unclassified HIGH 7.5
CVE-2026-40870

Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the root level `commentable` field…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified HIGH 7.1
CVE-2026-41192

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust client-supplied encrypted att…

Patch available
Fix from $1,950 2026-04-21
Unclassified MEDIUM 5.9
CVE-2026-40592

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}…

Patch available
Fix from $1,600 2026-04-21
Unclassified MEDIUM 5.7
CVE-2026-40570

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` …

Patch available
Fix from $1,600 2026-04-21
Neko HIGH 8.8
CVE-2026-39386

Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticat…

Fix: 3.0.11 / 3.1.2+
Fix from $1,950 2026-04-21
Openclaw MEDIUM 5.4
CVE-2026-41298

OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-bearing HTTP modes. Read-scoped ca…

Fix: 2026.4.2+
Fix from $1,600 2026-04-21
Magento MEDIUM 5.4
CVE-2026-40098

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo…

Fix: 20.17.0+
Fix from $1,600 2026-04-20
Vexa HIGH 7.5
CVE-2026-25058

Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector se…

Fix: after 0.10
Fix from $1,950 2026-04-20
Unclassified HIGH 8.1
CVE-2026-40581

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs per…

Patch available
Fix from $1,950 2026-04-18
Movary HIGH 8.8
CVE-2026-40349

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their…

Fix: 0.71.1+
Fix from $1,950 2026-04-18
Unclassified HIGH 7.1
CVE-2026-40480

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person re…

Patch available
Fix from $1,950 2026-04-18
Wger HIGH 7.6
CVE-2026-40474

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.ch…

Fix: 2.5+
Fix from $1,950 2026-04-17