Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Fleet MEDIUM 5.3
CVE-2026-24004

Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow una…

Fix: 4.80.1+
Fix from $1,600 2026-02-26
Live Helper Chat MEDIUM 6.5
CVE-2026-27954

Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints …

Fix: after 4.52
Fix from $1,600 2026-02-26
Zitadel MEDIUM 6.5
CVE-2026-27946

ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability a…

Fix: 3.4.7 / 4.11.0+
Fix from $1,600 2026-02-26
Openemr HIGH 8.1
CVE-2026-25164

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the REST API route t…

Fix: 8.0.0+
Fix from $1,950 2026-02-25
Youtrack MEDIUM 5.3
CVE-2026-28193

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

Fix: 2025.3.121962+
Fix from $1,600 2026-02-25
Enterprise Linux MEDIUM 5.5
CVE-2026-26104

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The…

Mitigation only
Fix from $1,600 2026-02-25
Enterprise Linux HIGH 7.1
CVE-2026-26103

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper aut…

Mitigation only
Fix from $1,950 2026-02-25
Unclassified HIGH 7.5
CVE-2026-1916

The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks …

Mitigation only
Fix from $1,950 2026-02-25
Parse Dashboard HIGH 8.1
CVE-2026-27608

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint…

Mitigation only
Fix from $1,950 2026-02-25
Openemr MEDIUM 6.5
CVE-2026-25124

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the OpenEMR applicat…

Fix: 8.0.0+
Fix from $1,600 2026-02-25
Openemr HIGH 8.8
CVE-2026-25131

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Cont…

Fix: 8.0.0+
Fix from $1,950 2026-02-25
Wyse Management Suite HIGH 8.8
CVE-2026-22765

Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access co…

Fix: 5.5+
Fix from $1,950 2026-02-24
Mastodon HIGH 8.2
CVE-2026-27468

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versio…

Fix: 4.4.14 / 4.5.7+
Fix from $1,950 2026-02-24
Unclassified MEDIUM 6.5
CVE-2025-14339

The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unau…

Mitigation only
Fix from $1,600 2026-02-21
Erpnext CRITICAL 9.1
CVE-2026-27471

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack…

Fix: 15.98.1 / 16.6.1+
Fix from $2,300 2026-02-21
Archiver CRITICAL 9.8
CVE-2026-2038

GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication…

Mitigation only
Fix from $2,300 2026-02-20
Archiver CRITICAL 9.8
CVE-2026-2039

GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authenticatio…

Mitigation only
Fix from $2,300 2026-02-20
Kargo MEDIUM 5.0
CVE-2026-27111

Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model includes a promote verb -- a non-…

Fix: 1.9.3+
Fix from $1,600 2026-02-20
Unclassified MEDIUM 6.5
CVE-2026-24946

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Inc…

Mitigation only
Fix from $1,600 2026-02-20
Unclassified HIGH 7.5
CVE-2026-24941

Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Level…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified MEDIUM 6.5
CVE-2026-24944

Missing Authorization vulnerability in weDevs Subscribe2 subscribe2 allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Mitigation only
Fix from $1,600 2026-02-20
Unclassified HIGH 7.5
CVE-2026-22351

Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectly Configured Access Control S…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified MEDIUM 6.5
CVE-2026-22350

Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Exploiting…

Mitigation only
Fix from $1,600 2026-02-20
Unclassified MEDIUM 6.5
CVE-2025-69388

Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Mitigation only
Fix from $1,600 2026-02-20
Unclassified HIGH 7.5
CVE-2025-69393

Missing Authorization vulnerability in Jthemes Exzo exzo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects E…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified MEDIUM 6.5
CVE-2025-69385

Missing Authorization vulnerability in AgniHD Cartify - WooCommerce Gutenberg WordPress Theme cartify allows Exploiting Incorrectly Configured Access…

Mitigation only
Fix from $1,600 2026-02-20
Unclassified HIGH 7.1
CVE-2025-69381

Missing Authorization vulnerability in vanquish WooCommerce Bulk Product Editor woocommerce-quick-product-editor allows Exploiting Incorrectly Config…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 7.5
CVE-2025-69303

Missing Authorization vulnerability in modeltheme ModelTheme Framework modeltheme-framework allows Exploiting Incorrectly Configured Access Control S…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 7.5
CVE-2025-69297

Missing Authorization vulnerability in GhostPool Aardvark Plugin aardvark-plugin allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 7.5
CVE-2025-69298

Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…

Mitigation only
Fix from $1,950 2026-02-20