Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-57400 Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorr… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-57390 Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Expl… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-57392 Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-57375 Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-57377 Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This is… Mitigation only Fix from $1,6002026-07-13 HIGH 7.5 CVE-2026-57378 Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Leve… Mitigation only Fix from $1,9502026-07-13 MEDIUM 5.4 CVE-2026-10085 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private… Mattermost Server 10.11.20 / 11.6.5+ Fix from $1,6002026-07-13 CRITICAL 9.1 CVE-2026-57830 Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulner… Helix Ultimate after 2.2.6 Fix from $2,3002026-07-13 HIGH 7.3 CVE-2026-15541 A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of… Patch available Fix from $1,9502026-07-13 MEDIUM 6.3 CVE-2026-15507 A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the compone… Mitigation only Fix from $1,6002026-07-12 HIGH 7.1 CVE-2026-61442 PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents,… Patch available Fix from $1,9502026-07-11 MEDIUM 5.3 CVE-2026-9017 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.3 CVE-2026-12994 The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. … Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.3 CVE-2026-6803 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12… Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.3 CVE-2026-6804 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12.… Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.3 CVE-2026-13250 The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin no… Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.4 CVE-2026-58589 Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. Flowdrop after 1.6.0 Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-58590 Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. Flowdrop 1.6.0+ Fix from $1,6002026-07-10 MEDIUM 5.3 CVE-2026-47422 Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and t… Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.3 CVE-2026-48127 Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through… Patch available Fix from $1,6002026-07-10 HIGH 7.1 CVE-2026-49394 Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace becau… Patch available Fix from $1,9502026-07-10 MEDIUM 6.5 CVE-2026-13239 Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from 0.0.0 to 4.2.0. Wisski 4.2+ Fix from $1,6002026-07-10 MEDIUM 6.5 CVE-2026-13240 Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. Paragraphs 1.21+ Fix from $1,6002026-07-10 MEDIUM 6.5 CVE-2026-13241 Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. Paragraphs 1.21+ Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-10768 Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0… Localgov Workflows 1.6.0+ Fix from $2,3002026-07-10 MEDIUM 5.0 CVE-2026-57221 RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive … Rabbitmq Server 4.2.6+ Fix from $1,6002026-07-10 MEDIUM 5.3 CVE-2026-13039 The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a … Mitigation only Fix from $1,6002026-07-10 HIGH 8.3 CVE-2026-57850 RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTran… Patch available Fix from $1,9502026-07-10 HIGH 7.7 CVE-2026-54329 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory m… Snipe It 8.6.2+ Fix from $1,9502026-07-10 HIGH 8.1 CVE-2026-56668 ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-typ… Patch available Fix from $1,9502026-07-10