Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.6 CVE-2026-55638 9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /co… Patch available Fix from $1,9502026-07-10 HIGH 7.2 CVE-2026-1667 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, a… Mitigation only Fix from $1,9502026-07-10 MEDIUM 6.5 CVE-2026-61441 PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either… Patch available Fix from $1,6002026-07-10 HIGH 8.1 CVE-2026-59796 In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks Teamcity 2026.1.2+ Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-56279 Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despit… Mitigation only Fix from $1,9502026-07-10 MEDIUM 5.3 CVE-2026-11990 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.3 CVE-2026-15332 A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of t… Mitigation only Fix from $1,6002026-07-10 HIGH 7.5 CVE-2026-15291 The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… Mitigation only Fix from $1,9502026-07-10 HIGH 8.0 CVE-2026-15293 The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due… Mitigation only Fix from $1,9502026-07-10 MEDIUM 5.5 CVE-2026-44918 OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization. Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-11818 The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions … Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-15320 A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pi… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.5 CVE-2026-59853 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria fr… Patch available Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-46413 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart u… Discourse 2026.1.5 / 2026.4.2+ Fix from $1,6002026-07-09 MEDIUM 5.5 CVE-2026-33802 A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-o… Junos Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.3 CVE-2026-54004 Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenti… Patch available Fix from $1,6002026-07-09 HIGH 7.1 CVE-2026-54005 Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowe… Patch available Fix from $1,9502026-07-09 MEDIUM 6.5 CVE-2026-54695 Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development… Pipecat 1.4.0+ Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-49274 Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access … Patch available Fix from $1,6002026-07-09 MEDIUM 5.4 CVE-2026-59227 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required on… Open Webui 0.10.0+ Fix from $1,6002026-07-09 MEDIUM 6.3 CVE-2026-59225 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user with… Open Webui 0.10.0+ Fix from $1,6002026-07-09 CRITICAL 9.0 CVE-2026-59216 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and ex… Open Webui 0.10.0+ Fix from $2,3002026-07-09 HIGH 8.7 CVE-2026-12593 The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for crea… Mitigation only Fix from $1,9502026-07-09 MEDIUM 5.3 CVE-2026-9028 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. Thi… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-9021 The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin regi… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-12428 The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values()… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-7558 The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and in… Mitigation only Fix from $1,6002026-07-09 HIGH 7.2 CVE-2026-8848 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorizatio… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.5 CVE-2026-8996 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … Mitigation only Fix from $1,6002026-07-09 CRITICAL 9.8 CVE-2026-14245 The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Acc… Mitigation only Fix from $2,3002026-07-09