Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2026-32332

Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.3
CVE-2026-32334

Missing Authorization vulnerability in raratheme JobScout jobscout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.3
CVE-2026-31915

Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.3
CVE-2026-31916

Missing Authorization vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Exploiting Incorrectly Configured Access Contro…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified HIGH 7.5
CVE-2026-2890

The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the …

Mitigation only
Fix from $1,950 2026-03-13
Wpdiscuz HIGH 7.5
CVE-2026-22182

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by…

Fix: 7.6.47+
Fix from $1,950 2026-03-13
Uptime Kuma MEDIUM 5.3
CVE-2026-32230

Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration? endpoint in server/routers/a…

Fix: 2.2.0+
Fix from $1,600 2026-03-12
Tracer Sc Firmware HIGH 7.5
CVE-2026-28254

A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitiv…

Fix: 6.3.2310+
Fix from $1,950 2026-03-12
Veeam Backup \& Replication MEDIUM 6.5
CVE-2026-21668

A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

Fix: 12.3.2.4465+
Fix from $1,600 2026-03-12
Unclassified MEDIUM 6.3
CVE-2026-3977

A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. T…

Patch available
Fix from $1,600 2026-03-12
Zitadel HIGH 7.7
CVE-2026-32131

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, whi…

Fix: 3.4.8 / 4.12.2+
Fix from $1,950 2026-03-11
Openemr HIGH 8.1
CVE-2026-32126

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condit…

Fix: 8.0.0.1+
Fix from $1,950 2026-03-11
Fileexplorer CRITICAL 9.8
CVE-2026-29515

MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log …

Mitigation only
Fix from $2,300 2026-03-11
Unclassified MEDIUM 6.5
CVE-2026-1781

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.11.1. This is …

Patch available
Fix from $1,600 2026-03-11
Umbraco Cms HIGH 7.2
CVE-2026-31834

Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under ce…

Fix: 16.5.1 / 17.2.2+
Fix from $1,950 2026-03-10
Sylius MEDIUM 5.3
CVE-2026-31821

Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does not verify cart ownership. An …

Fix: 2.0.16 / 2.1.12+
Fix from $1,600 2026-03-10
Parse Server CRITICAL 9.1
CVE-2026-31800

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.12 and 8.6.25, the _Grap…

Fix: 8.6.25 / 9.5.2+
Fix from $2,300 2026-03-10
Px4 Drone Autopilot HIGH 8.1
CVE-2026-26741

PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while…

Fix: 1.16.0+
Fix from $1,950 2026-03-10
Px4 Drone Autopilot HIGH 8.1
CVE-2026-26742

PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applie…

Fix: 1.16.0+
Fix from $1,950 2026-03-10
Oneuptime MEDIUM 5.0
CVE-2026-30959

OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a…

Fix: 10.0.21+
Fix from $1,600 2026-03-10
Coral Server CRITICAL 9.8
CVE-2026-30968

Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1…

Fix: 1.1.0+
Fix from $2,300 2026-03-10
Coral Server CRITICAL 9.1
CVE-2026-30970

Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1…

Fix: 1.1.0+
Fix from $2,300 2026-03-10
Oneuptime CRITICAL 9.9
CVE-2026-30956

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isol…

Fix: 10.0.21+
Fix from $2,300 2026-03-10
Oneuptime HIGH 8.6
CVE-2026-30920

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled sta…

Fix: 10.0.19+
Fix from $1,950 2026-03-10
Avideo MEDIUM 5.3
CVE-2026-30885

WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user with…

Fix: 25.0+
Fix from $1,600 2026-03-10
Unclassified MEDIUM 5.9
CVE-2026-27686

Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an aff…

Mitigation only
Fix from $1,600 2026-03-10
Unclassified MEDIUM 5.8
CVE-2026-27687

Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belo…

Mitigation only
Fix from $1,600 2026-03-10
Netweaver Application Server Abap MEDIUM 5.0
CVE-2026-27688

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database…

Mitigation only
Fix from $1,600 2026-03-10
Unclassified MEDIUM 5.0
CVE-2026-24313

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allow…

Mitigation only
Fix from $1,600 2026-03-10
Netweaver Application Server Abap MEDIUM 6.4
CVE-2026-24309

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function modul…

Mitigation only
Fix from $1,600 2026-03-10