Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Soft Serve MEDIUM 6.5
CVE-2026-33353

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allo…

Fix: 0.11.6+
Fix from $1,600 2026-03-24
\@astrojs\/vercel CRITICAL 9.1
CVE-2026-33768

Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query par…

Fix: 10.0.2+
Fix from $2,300 2026-03-24
Craft Cms MEDIUM 5.3
CVE-2026-33160

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …

Fix: 4.17.8 / 5.9.14+
Fix from $1,600 2026-03-24
Craft Cms MEDIUM 6.5
CVE-2026-33162

Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp c…

Fix: 5.9.14+
Fix from $1,600 2026-03-24
Craft Cms MEDIUM 6.5
CVE-2026-33159

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …

Fix: 4.17.8 / 5.9.14+
Fix from $1,600 2026-03-24
Vikunja HIGH 8.1
CVE-2026-33316

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled user…

Fix: 2.2.0+
Fix from $1,950 2026-03-24
Langflow HIGH 7.5
CVE-2026-33484EPSS 6%

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{…

Fix: 1.9.0+
Fix from $1,950 2026-03-24
Unclassified CRITICAL 9.1
CVE-2026-4283

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This i…

Mitigation only
Fix from $2,300 2026-03-24
Unclassified MEDIUM 6.5
CVE-2026-3138

The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versi…

Mitigation only
Fix from $1,600 2026-03-24
Unclassified MEDIUM 5.4
CVE-2026-4056

The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the C…

Mitigation only
Fix from $1,600 2026-03-24
Avideo MEDIUM 5.3
CVE-2026-33685

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.php` endpoint performs no auth…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo MEDIUM 5.3
CVE-2026-33501

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/li…

Fix: after 26.0
Fix from $1,600 2026-03-23
Unclassified HIGH 8.8
CVE-2026-4261

The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin al…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified MEDIUM 5.3
CVE-2026-3651

The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. This is due to the plugi…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 5.3
CVE-2026-3645

The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.1. The save_c…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 5.3
CVE-2026-3570

The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing aut…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 5.3
CVE-2026-3506

The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9. This is due to the…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 5.3
CVE-2026-3335

The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified HIGH 8.8
CVE-2026-2941

The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'links…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified MEDIUM 6.5
CVE-2026-2720

The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 5.3
CVE-2026-3567

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. T…

Mitigation only
Fix from $1,600 2026-03-21
Discourse MEDIUM 5.3
CVE-2026-33425

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenticated users can determine whe…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-21
Discourse HIGH 7.5
CVE-2026-33427

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthenticated attacker can cause a…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,950 2026-03-21
Openclaw CRITICAL 9.9
CVE-2026-22172

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password…

Fix: 2026.3.12+
Fix from $2,300 2026-03-20
Unclassified MEDIUM 5.3
CVE-2026-3550

The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. This is due to missing capabi…

Mitigation only
Fix from $1,600 2026-03-20
Unclassified CRITICAL 9.8
CVE-2026-4038

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check…

Mitigation only
Fix from $2,300 2026-03-20
Admidio CRITICAL 9.1
CVE-2026-32817

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the curre…

Fix: 5.0.7+
Fix from $2,300 2026-03-20
Admidio MEDIUM 6.5
CVE-2026-32818

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does not verify whether the current …

Fix: 5.0.7+
Fix from $1,600 2026-03-19
Discourse HIGH 7.5
CVE-2026-29072

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed …

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,950 2026-03-19
Openemr MEDIUM 6.5
CVE-2026-33304

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in…

Fix: 8.0.0.2+
Fix from $1,600 2026-03-19