Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.0 CVE-2026-16799 Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticat… Powershell Universal 2026.2.3.0+ Fix from $1,6002026-07-24 HIGH 7.3 CVE-2026-10033 The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the p… No fix yet Fix from $1,9502026-07-24 MEDIUM 5.3 CVE-2026-12654 The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. Th… No fix yet Fix from $1,6002026-07-24 MEDIUM 5.4 CVE-2026-12689 The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions,… No fix yet Fix from $1,6002026-07-24 MEDIUM 5.3 CVE-2026-11354 The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the … No fix yet Fix from $1,6002026-07-24 CRITICAL 9.8 CVE-2026-58275 Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. Azure Dns No fix yet Fix from $2,3002026-07-24 CRITICAL 9.9 CVE-2026-47724 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trust… Mitigation only Fix from $2,3002026-07-23 MEDIUM 6.5 CVE-2026-47755 ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged auth… No fix yet Fix from $1,6002026-07-23 HIGH 8.1 CVE-2026-65916 CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows aut… No fix yet Fix from $1,9502026-07-23 HIGH 8.5 CVE-2026-65895 Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users w… No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-65525 Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-65529 Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-65499 Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-65500 Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-65506 Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-65489 Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions. No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-65495 Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. No fix yet Fix from $1,9502026-07-23 MEDIUM 6.3 CVE-2026-65484 Contributor Broken Access Control in Style Kits <= 2.6.5 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-65485 Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-65486 Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-65487 Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-65476 Unauthenticated Broken Access Control in Civi <= 2.2.4 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-65478 Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-65479 Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-65468 Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-65469 Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-65472 Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions. No fix yet Fix from $1,6002026-07-23 HIGH 8.6 CVE-2026-64814 In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session Intellij Idea 2026.2+ Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-65452 Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-65453 Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. No fix yet Fix from $1,6002026-07-23