Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2026-34261

Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to cer…

Mitigation only
Fix from $1,600 2026-04-14
Unclassified MEDIUM 6.5
CVE-2026-27677

Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could update and delete child entities…

Mitigation only
Fix from $1,600 2026-04-14
Unclassified MEDIUM 6.5
CVE-2026-27678

Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker could update and delete child…

Mitigation only
Fix from $1,600 2026-04-14
Manage Reference Structures MEDIUM 6.5
CVE-2026-27679

Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete chil…

Mitigation only
Fix from $1,600 2026-04-14
Metagpt HIGH 8.8
CVE-2026-6109

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environ…

Fix: after 0.8.1
Fix from $1,950 2026-04-12
Unclassified MEDIUM 5.4
CVE-2026-3358

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course enrollment in all versions up …

Mitigation only
Fix from $1,600 2026-04-11
Trek MEDIUM 6.5
CVE-2026-40185

TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo management routes. This vulner…

Fix: after 2.7.1
Fix from $1,600 2026-04-10
Goshs CRITICAL 9.8
CVE-2026-40189

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for direct…

Fix: 2.0.0+
Fix from $2,300 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-33708

Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email,…

Fix: 1.11.38+
Fix from $1,600 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-33141

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endp…

Fix: after 1.11.38
Fix from $1,600 2026-04-10
Openclaw HIGH 8.1
CVE-2026-35660

OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint that allows callers with operato…

Fix: 2026.3.23+
Fix from $1,950 2026-04-10
Openclaw MEDIUM 5.4
CVE-2026-35620

OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows …

Fix: 2026.3.24+
Fix from $1,600 2026-04-10
Openclaw MEDIUM 6.5
CVE-2026-35621

OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validate gateway client scopes for i…

Fix: 2026.3.24+
Fix from $1,600 2026-04-10
Unclassified HIGH 7.1
CVE-2026-4162

The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not p…

Mitigation only
Fix from $1,950 2026-04-10
Unclassified HIGH 7.5
CVE-2026-3360

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to,…

Mitigation only
Fix from $1,950 2026-04-10
Praisonaiagents HIGH 7.5
CVE-2026-40117

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesyst…

Fix: 1.5.128+
Fix from $1,950 2026-04-09
Openclaw MEDIUM 6.5
CVE-2026-35631

OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attacker…

Fix: 2026.3.22+
Fix from $1,600 2026-04-09
Junos HIGH 8.8
CVE-2026-33785

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to …

Mitigation only
Fix from $1,950 2026-04-09
Junos MEDIUM 5.5
CVE-2026-33776

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read se…

Fix: 22.4 / 23.2+
Fix from $1,600 2026-04-09
Openplc V3 Firmware HIGH 8.8
CVE-2026-35063

OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other…

Mitigation only
Fix from $1,950 2026-04-09
Control System CRITICAL 9.1
CVE-2026-34184

AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and ev…

Fix: 9.8.5+
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.8
CVE-2026-1830EPSS 8%

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insuffic…

Mitigation only
Fix from $2,300 2026-04-09
Unclassified MEDIUM 5.4
CVE-2026-4124

The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The wp_ajax_ziggeo_ajax handler …

Mitigation only
Fix from $1,600 2026-04-09
Unclassified HIGH 8.8
CVE-2026-4326

The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to…

Mitigation only
Fix from $1,950 2026-04-09
Kcp CRITICAL 9.1
CVE-2026-39429

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cach…

Fix: 0.29.3 / 0.30.3+
Fix from $2,300 2026-04-08
Xwiki CRITICAL 9.8
CVE-2026-33229

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly p…

Fix: 17.4.8 / 17.10.1+
Fix from $2,300 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-39713

Missing Authorization vulnerability in mailercloud Mailercloud – Integrate webforms and synchronize website contacts mailercloud-integrate-webforms-s…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-39714

Missing Authorization vulnerability in G5Theme G5Plus April g5plus-april allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-39715

Missing Authorization vulnerability in AnyTrack AnyTrack Affiliate Link Manager anytrack-affiliate-link-manager allows Exploiting Incorrectly Configu…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-39716

Missing Authorization vulnerability in CKThemes Flipmart flipmart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

No fix yet
Fix from $1,600 2026-04-08