Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-9132 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private … Enterprise Server 3.17.17 / 3.18.11+ Fix from $1,6002026-06-30 HIGH 8.1 CVE-2026-58377 JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, up… Mitigation only Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-58176 RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without an… Patch available Fix from $1,6002026-06-30 HIGH 8.8 CVE-2026-58165 OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fi… Patch available Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-58167 Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-… Patch available Fix from $1,6002026-06-30 HIGH 8.8 CVE-2026-58168 DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due t… Patch available Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-54475 Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations … Activemq 5.19.8 / 6.2.7+ Fix from $1,9502026-06-30 MEDIUM 5.3 CVE-2026-12349 The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including… Mitigation only Fix from $1,6002026-06-30 CRITICAL 9.6 CVE-2026-57498 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controller… Mitigation only Fix from $2,3002026-06-29 MEDIUM 6.5 CVE-2026-57952 Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rule… Mythic 3.4.0.60+ Fix from $1,6002026-06-29 MEDIUM 6.5 CVE-2026-57949 ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-… Patch available Fix from $1,6002026-06-29 MEDIUM 6.5 CVE-2026-57339 Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions. Mitigation only Fix from $1,6002026-06-29 MEDIUM 6.5 CVE-2026-57340 Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions. Mitigation only Fix from $1,6002026-06-29 HIGH 7.1 CVE-2026-57332 Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. Mitigation only Fix from $1,9502026-06-29 MEDIUM 6.5 CVE-2026-57334 Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. No fix yet Fix from $1,6002026-06-29 MEDIUM 6.5 CVE-2026-57335 Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions. Mitigation only Fix from $1,6002026-06-29 MEDIUM 6.3 CVE-2026-57327 Subscriber Broken Access Control in MainWP <= 6.1.1 versions. Mitigation only Fix from $1,6002026-06-29 HIGH 8.3 CVE-2025-2902 Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform… Mitigation only Fix from $1,9502026-06-29 HIGH 8.8 CVE-2026-13484 A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component… Mlflow after 2026-05-26 Fix from $1,9502026-06-28 MEDIUM 5.3 CVE-2026-12432 The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_faile… Mitigation only Fix from $1,6002026-06-27 MEDIUM 6.5 CVE-2026-3462 The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'pro… Mitigation only Fix from $1,6002026-06-27 MEDIUM 5.3 CVE-2026-12404 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … Mitigation only Fix from $1,6002026-06-27 CRITICAL 9.4 CVE-2026-50137 Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-so… Budibase 3.39.0+ Fix from $2,3002026-06-26 HIGH 8.2 CVE-2026-55188 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bu… Mitigation only Fix from $1,9502026-06-26 HIGH 7.7 CVE-2026-55189 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read an… Mitigation only Fix from $1,9502026-06-26 HIGH 8.6 CVE-2026-49991 RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket … Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-47193 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical … Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-44734 OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenPr… Mitigation only Fix from $1,6002026-06-26 HIGH 8.8 CVE-2026-57518 Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate… Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.6 CVE-2026-12411 Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gu… Lxd 6.9+ Fix from $2,3002026-06-26