Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.1 CVE-2026-3141 The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/re… No fix yet Fix from $2,3002026-08-01 MEDIUM 5.4 CVE-2026-45086 Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.4 CVE-2026-17350 The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consist… Pgadmin 4 9.17+ Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-15227 Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" per… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-18436 The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore RES… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-18437 The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.4 CVE-2026-18218 A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a spe… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-18208 A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access manageme… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 HIGH 8.1 CVE-2026-18214 Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was fo… Build Of Keycloak No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-14930 The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allo… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.3 CVE-2026-14317 The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it… No fix yet Fix from $1,6002026-07-31 HIGH 7.6 CVE-2026-67527 OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and al… No fix yet Fix from $1,9502026-07-30 HIGH 7.2 CVE-2026-15397 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is du… No fix yet Fix from $1,9502026-07-30 MEDIUM 5.4 CVE-2026-15252 The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authentic… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-11867 The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and d… No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-12500 The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress … No fix yet Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-14356 The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin … Mitigation only Fix from $1,9502026-07-30 HIGH 7.1 CVE-2026-16543 Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-w… No fix yet Fix from $1,9502026-07-29 HIGH 7.1 CVE-2026-15228 Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-66724 MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoi… No fix yet Fix from $1,6002026-07-29 HIGH 7.0 CVE-2026-66723 MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-4604 The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_… No fix yet Fix from $1,6002026-07-29 CRITICAL 9.1 CVE-2026-14488 The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission exten… No fix yet Fix from $2,3002026-07-29 HIGH 8.8 CVE-2026-50622 Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated … Atlas 2.6.0+ Fix from $1,9502026-07-29 MEDIUM 5.5 CVE-2026-18201 Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator w… Build Of Keycloak No fix yet Fix from $1,6002026-07-29 MEDIUM 5.3 CVE-2026-13692 The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing… No fix yet Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-54719 goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?… No fix yet Fix from $1,9502026-07-28 CRITICAL 9.8 CVE-2026-16184 IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 HIGH 8.8 CVE-2026-49258 Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-oper… No fix yet Fix from $1,9502026-07-28 MEDIUM 5.4 CVE-2026-66751 Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server … No fix yet Fix from $1,6002026-07-28