Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-12406 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authori… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-48492 Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorizati… Snipe It 8.6.0+ Fix from $1,6002026-07-08 CRITICAL 9.8 CVE-2026-31309 Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to… Patch available Fix from $2,3002026-07-08 HIGH 8.1 CVE-2026-35552 In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administ… Mitigation only Fix from $1,9502026-07-08 MEDIUM 5.3 CVE-2026-7492 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under … GitLab 18.11.7 / 19.0.4+ Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-59805 Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate… Patch available Fix from $1,6002026-07-08 HIGH 7.7 CVE-2026-14373 HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This … Mitigation only Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-59262 AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace member… Patch available Fix from $1,6002026-07-08 MEDIUM 5.3 CVE-2026-60124 An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persis… Patch available Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-56250 Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbit… Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-5356 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions u… Mitigation only Fix from $1,9502026-07-08 MEDIUM 5.3 CVE-2026-12097 The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin n… Mitigation only Fix from $1,6002026-07-08 CRITICAL 9.8 CVE-2026-12153 The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugi… Mitigation only Fix from $2,3002026-07-08 MEDIUM 5.4 CVE-2026-55432 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `Cre… Coder 2.29.17 / 2.32.7+ Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-55433 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devc… Coder 2.29.17 / 2.32.7+ Fix from $1,6002026-07-08 HIGH 7.1 CVE-2026-59704 Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summarie… Patch available Fix from $1,9502026-07-07 CRITICAL 9.1 CVE-2026-58473 Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider conf… Patch available Fix from $2,3002026-07-07 MEDIUM 6.9 CVE-2026-55417 Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile opti… Mitigation only Fix from $1,6002026-07-07 HIGH 8.7 CVE-2026-53730 DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @D… Patch available Fix from $1,9502026-07-07 HIGH 7.2 CVE-2026-50007 Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared user with user_access on a budg… Patch available Fix from $1,9502026-07-07 HIGH 7.5 CVE-2026-59708 The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing una… Patch available Fix from $1,9502026-07-07 HIGH 8.3 CVE-2026-11340 Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects L… Mitigation only Fix from $1,9502026-07-07 HIGH 8.2 CVE-2026-8377 Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource … Mitigation only Fix from $1,9502026-07-07 CRITICAL 9.9 CVE-2026-34048 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket boots… Patch available Fix from $2,3002026-07-07 MEDIUM 6.9 CVE-2026-53647 FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endp… Mitigation only Fix from $1,6002026-07-07 HIGH 8.7 CVE-2026-53643 FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unaut… Mitigation only Fix from $1,9502026-07-06 MEDIUM 6.5 CVE-2026-34050 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Liv… Patch available Fix from $1,6002026-07-06 HIGH 7.8 CVE-2026-6509 Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue… Mitigation only Fix from $1,9502026-07-05 HIGH 8.2 CVE-2026-27771EPSS 43% Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal… Patch available Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-25038 Gitea 1.26.2 allows unauthorized users to access labels of private organizations. Patch available Fix from $1,9502026-07-03