Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2026-3098

The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll'…

Mitigation only
Fix from $1,600 2026-03-27
Open Webui HIGH 8.1
CVE-2026-29070

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an access control check is…

Fix: 0.8.6+
Fix from $1,950 2026-03-27
Ech0 MEDIUM 5.3
CVE-2026-33638

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/allusers` is mounted as a public…

Fix: 4.2.0+
Fix from $1,600 2026-03-26
Clearancekit HIGH 8.7
CVE-2026-33631

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the o…

Fix: 4.2+
Fix from $1,950 2026-03-26
Clearancekit HIGH 7.8
CVE-2026-33632

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.4, two file operation event…

Fix: 4.2.4+
Fix from $1,950 2026-03-26
Oathkeeper MEDIUM 6.5
CVE-2026-33495

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Ory O…

Fix: 26.2.0+
Fix from $1,600 2026-03-26
Etcd HIGH 8.8
CVE-2026-33413

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypas…

Fix: 3.4.42 / 3.5.28+
Fix from $1,950 2026-03-26
Unclassified MEDIUM 5.3
CVE-2026-4281

The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. Thi…

Mitigation only
Fix from $1,600 2026-03-26
Unclassified HIGH 8.8
CVE-2026-4484

The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin a…

Mitigation only
Fix from $1,950 2026-03-26
Openemr HIGH 8.1
CVE-2026-34053

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorizat…

Fix: 8.0.0.3+
Fix from $1,950 2026-03-26
Openemr MEDIUM 5.4
CVE-2026-33915

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance com…

Fix: 8.0.0.3+
Fix from $1,600 2026-03-26
Openemr HIGH 8.8
CVE-2026-33918

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-d…

Fix: 8.0.0.3+
Fix from $1,950 2026-03-26
Unclassified HIGH 7.5
CVE-2026-32546

Missing Authorization vulnerability in StellarWP Restrict Content restrict-content allows Exploiting Incorrectly Configured Access Control Security L…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified MEDIUM 5.4
CVE-2026-32562

Missing Authorization vulnerability in WP Folio Team PPWP password-protect-page allows Exploiting Incorrectly Configured Access Control Security Leve…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-32541

Missing Authorization vulnerability in Premmerce Premmerce Redirect Manager premmerce-redirect-manager allows Exploiting Incorrectly Configured Acces…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-32527

Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-32514

Missing Authorization vulnerability in Anton Voytenko Petitioner petitioner allows Exploiting Incorrectly Configured Access Control Security Levels.T…

No fix yet
Fix from $1,600 2026-03-25
Unclassified HIGH 7.5
CVE-2026-32515

Missing Authorization vulnerability in kamleshyadav Miraculous miraculous allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 7.1
CVE-2026-32501

Missing Authorization vulnerability in wp-configurator WP Configurator Pro wp-configurator-pro allows Exploiting Incorrectly Configured Access Contro…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 7.5
CVE-2026-32495

Missing Authorization vulnerability in Link Software LLC WP Terms Popup wp-terms-popup allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 7.5
CVE-2026-32498

Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorre…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 7.7
CVE-2026-32441

Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-32483

Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Se…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified HIGH 7.5
CVE-2026-32485

Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Leve…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-32489

Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

No fix yet
Fix from $1,600 2026-03-25
Unclassified HIGH 8.2
CVE-2026-31921

Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorre…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified CRITICAL 9.1
CVE-2026-27071

Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-27046

Missing Authorization vulnerability in Kaira StoreCustomizer woocustomizer allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.3
CVE-2026-25460

Missing Authorization vulnerability in LiquidThemes Ave Core ave-core allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-25462

Missing Authorization vulnerability in avalex avalex avalex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect…

Mitigation only
Fix from $1,600 2026-03-25