Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2026-11907

The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not prop…

No fix yet
Fix from $1,600 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-14365

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu…

No fix yet
Fix from $2,300 2026-08-07
Teams CRITICAL 10.0
CVE-2026-65667

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Sre Agent CRITICAL 9.9
CVE-2026-62830

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Unclassified HIGH 7.5
CVE-2026-70636

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh e…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.6
CVE-2026-67621

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document sto…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-64662

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view con…

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-48085

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provision…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.4
CVE-2026-48088

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /…

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-48077

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler a…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-48075

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunne…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.1
CVE-2026-47765

Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate …

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.0
CVE-2026-45415

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_censu…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.5
CVE-2026-13399

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unau…

No fix yet
Fix from $1,950 2026-08-06
Escriptorium HIGH 7.1
CVE-2026-18277

Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to gran…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-66712

Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.2
CVE-2026-66708

Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-66699

Custom role Broken Access Control in Dokan <= 5.0.10 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-66701

Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-66452

Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66470

Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-65554

Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.3
CVE-2026-65541

Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-65504

Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-32548

Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.5
CVE-2026-28140

Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-25403

Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-28005

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 7.5
CVE-2026-65551

Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-11983

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 du…

No fix yet
Fix from $1,600 2026-08-06