Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Openemr MEDIUM 5.4
CVE-2026-33305

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in…

Fix: 8.0.0.2+
Fix from $1,600 2026-03-19
Sqlbot HIGH 8.8
CVE-2026-32622

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulner…

Fix: 1.6.0+
Fix from $1,950 2026-03-19
Discourse MEDIUM 5.3
CVE-2026-27454

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X by…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-19
Kibana MEDIUM 6.5
CVE-2026-26939

Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (ho…

Fix: 8.19.12 / 9.2.6+
Fix from $1,600 2026-03-19
Unclassified HIGH 7.5
CVE-2026-25443

Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers a…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified MEDIUM 5.3
CVE-2026-3475

The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all versions up to and including 1.1…

Mitigation only
Fix from $1,600 2026-03-19
Unclassified HIGH 7.5
CVE-2026-25312

Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Cont…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified MEDIUM 6.3
CVE-2026-27091

Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Mitigation only
Fix from $1,600 2026-03-19
Unclassified MEDIUM 5.3
CVE-2026-28070

Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Mitigation only
Fix from $1,600 2026-03-19
Unclassified MEDIUM 5.3
CVE-2026-2559

The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oaut…

Mitigation only
Fix from $1,600 2026-03-18
Unclassified HIGH 8.2
CVE-2026-2992

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on th…

Mitigation only
Fix from $1,950 2026-03-18
Unclassified MEDIUM 5.3
CVE-2026-32565

Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrectly Configured Access Control…

Mitigation only
Fix from $1,600 2026-03-18
Unclassified MEDIUM 5.4
CVE-2026-1217

The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_…

Mitigation only
Fix from $1,600 2026-03-18
Unclassified HIGH 8.7
CVE-2026-32268

The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, u…

Patch available
Fix from $1,950 2026-03-18
Unclassified MEDIUM 5.3
CVE-2026-1926

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `w…

Mitigation only
Fix from $1,600 2026-03-18
Powershell Universal HIGH 8.3
CVE-2026-4064

Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid t…

Fix: 2026.1.4+
Fix from $1,950 2026-03-17
Airflow HIGH 8.1
CVE-2026-30911

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows…

Fix: 3.1.8+
Fix from $1,950 2026-03-17
Unclassified MEDIUM 5.3
CVE-2026-32586

Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectly Configured Access Control S…

Mitigation only
Fix from $1,600 2026-03-17
Unclassified MEDIUM 5.3
CVE-2026-2373

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up…

Mitigation only
Fix from $1,600 2026-03-17
Unclassified MEDIUM 5.3
CVE-2026-32583

Missing Authorization vulnerability in Webnus Inc. Modern Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified MEDIUM 5.4
CVE-2026-32587

Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified MEDIUM 5.3
CVE-2026-2233

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unautho…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified HIGH 8.3
CVE-2026-25083

GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified MEDIUM 5.3
CVE-2026-1870

The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a m…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified HIGH 7.5
CVE-2026-3045

The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all ve…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified MEDIUM 5.3
CVE-2026-32487

Missing Authorization vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Exploiting Incorrectly Configured Access Control Secu…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.3
CVE-2026-32543

Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting Incorrectly Configured Access C…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.3
CVE-2026-32486

Missing Authorization vulnerability in wptravelengine Travel Booking travel-booking allows Exploiting Incorrectly Configured Access Control Security …

No fix yet
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.3
CVE-2026-32457

Missing Authorization vulnerability in Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce advanced-product-fields-for-woocommerc…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2026-32451

Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2026-03-13