Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2026-72900

Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

No fix yet
Fix from $4,000 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72737

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs …

No fix yet
Fix from $5,750 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-72723

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_men…

No fix yet
Fix from $4,000 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-47754

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions conta…

No fix yet
Fix from $5,750 2026-08-10
Unclassified MEDIUM 6.9
CVE-2026-72759

In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.8
CVE-2026-71959

Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72692

A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-19404

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization …

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-17021

The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 8.1
CVE-2026-18030

The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-14941

The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX act…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-15237

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payme…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-19350

A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component Ta…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 6.5
CVE-2026-19345

A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manip…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 6.5
CVE-2026-18603

The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding …

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 6.5
CVE-2026-18037

The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 6.5
CVE-2026-16992

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that r…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-16608

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 6.5
CVE-2026-47127

Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/sub…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.8
CVE-2026-48169

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break wo…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.7
CVE-2026-64676

Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the …

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.1
CVE-2026-66060

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.1
CVE-2026-66061

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag lin…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.8
CVE-2026-19017

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-66058

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is poss…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.9
CVE-2026-17601

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader per…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.9
CVE-2026-54201

Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attacke…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.5
CVE-2026-16041

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route,…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.5
CVE-2026-15359

The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers…

No fix yet
Fix from $1,600 2026-08-07
Unclassified CRITICAL 9.1
CVE-2026-16038

The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its…

No fix yet
Fix from $2,300 2026-08-07