Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.4 CVE-2026-66589 Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue aff… Fix unknown Fix from $4,0002026-08-18 HIGH 8.7 CVE-2026-53453 Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intende… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-12631 The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_… Fix unknown Fix from $4,0002026-08-18 HIGH 7.7 CVE-2026-71307 Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibl… Fix unknown Fix from $4,9002026-08-18 HIGH 8.1 CVE-2026-71308 Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements ide… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-71317 Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent aut… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.9 CVE-2026-67440 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERF… Fix unknown Fix from $4,0002026-08-18 CRITICAL 9.2 CVE-2026-67443 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integ… Fix unknown Fix from $5,7502026-08-18 MEDIUM 6.3 CVE-2026-47721 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-65959 Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoin… Fix unknown Fix from $4,0002026-08-18 HIGH 8.1 CVE-2026-67262 Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read fro… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-55106 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.4 CVE-2026-74004 Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions. Fix unknown Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-73994 Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-73404 Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. Fix unknown Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-73377 Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-73348 Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-73352 Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions. Fix unknown Fix from $4,0002026-08-18 HIGH 8.2 CVE-2026-73356 Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.6 CVE-2026-69189 Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, c… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-66651 Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions. Fix unknown Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-32549 Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-32472 Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-28567 Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-28571 Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-75846 ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunct… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-75853 ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no au… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-75836 The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in M… Fix unknown Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-74904 SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockE… Fix unknown Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-11801 The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is du… Fix unknown Fix from $4,9002026-08-18