Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-12723 The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overw… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.5 CVE-2026-16215 A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Ha… No fix yet Fix from $1,6002026-07-19 MEDIUM 6.3 CVE-2026-16197 A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/… No fix yet Fix from $1,6002026-07-18 MEDIUM 6.3 CVE-2026-16123 A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the fi… No fix yet Fix from $1,6002026-07-18 CRITICAL 9.6 CVE-2026-55518 Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_… No fix yet Fix from $2,3002026-07-17 HIGH 7.1 CVE-2026-45704 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization bet… No fix yet Fix from $1,9502026-07-17 HIGH 8.1 CVE-2026-45260 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE op… Mitigation only Fix from $1,9502026-07-17 MEDIUM 6.4 CVE-2026-45703 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportB… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-48014 Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{trans… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-48008 Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to fu… No fix yet Fix from $1,6002026-07-17 CRITICAL 9.1 CVE-2026-12694 Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This… No fix yet Fix from $2,3002026-07-17 MEDIUM 6.5 CVE-2026-63100 Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify glo… No fix yet Fix from $1,6002026-07-17 MEDIUM 5.3 CVE-2026-15783 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any reposito… No fix yet Fix from $1,6002026-07-17 HIGH 8.5 CVE-2026-12715 Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other user… Mitigation only Fix from $1,9502026-07-17 MEDIUM 6.3 CVE-2026-16017 A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the compo… No fix yet Fix from $1,6002026-07-17 HIGH 7.5 CVE-2026-11575 The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used … No fix yet Fix from $1,9502026-07-17 HIGH 7.5 CVE-2026-13765 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all … No fix yet Fix from $1,9502026-07-17 MEDIUM 5.3 CVE-2026-8616 The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing n… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.3 CVE-2026-62235 Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with… No fix yet Fix from $1,6002026-07-17 HIGH 7.4 CVE-2026-62232 Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user e… No fix yet Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-62233 grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.user… No fix yet Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-62218 OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers … Openclaw 2026.5.27+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-62207 OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attacke… Openclaw 2026.6.5+ Fix from $1,9502026-07-17 HIGH 7.1 CVE-2026-62205 OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the af… Openclaw 2026.6.6+ Fix from $1,9502026-07-17 HIGH 7.1 CVE-2026-62206 OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust ca… Openclaw 2026.6.9+ Fix from $1,9502026-07-17 MEDIUM 5.3 CVE-2026-45334 Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature returned lock information withou… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.0 CVE-2026-44176 Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft re… No fix yet Fix from $1,6002026-07-16 MEDIUM 5.4 CVE-2026-61718 bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware autho… No fix yet Fix from $1,6002026-07-16 CRITICAL 9.3 CVE-2026-46515 Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pin… Mitigation only Fix from $2,3002026-07-16 MEDIUM 5.4 CVE-2026-63082 Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers… No fix yet Fix from $1,6002026-07-16