Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-54027 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authen… Librechat after 0.8.3 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-54029 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId e… Librechat after 0.8.3 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-48941 The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` c… K2 after 2.26 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-57619 Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. Mitigation only Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-57429 Contributor Broken Access Control in Slim SEO <= 4.6.2 versions. Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.4 CVE-2026-56023 Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions. Mitigation only Fix from $1,6002026-06-25 HIGH 8.1 CVE-2026-54842 Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue a… Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-54844 Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-54830 Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-54828 Unauthenticated Broken Access Control in Motors <= 1.4.109 versions. Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-27366 Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions. Mitigation only Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-2238 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under… GitLab 18.11.6 / 19.0.3+ Fix from $1,6002026-06-25 HIGH 8.1 CVE-2026-55762 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, th… Mitigation only Fix from $1,9502026-06-24 HIGH 7.1 CVE-2026-52812 Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS-root>/<oid[0]>/<oid[1]>/<oid… Patch available Fix from $1,9502026-06-24 HIGH 7.5 CVE-2026-52799 Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the… Mitigation only Fix from $1,9502026-06-24 HIGH 8.7 CVE-2026-45677 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1… Mitigation only Fix from $1,9502026-06-24 HIGH 7.1 CVE-2026-27708 FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method ac… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.4 CVE-2026-57304 A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifi… Assembla after 1.4 Fix from $1,6002026-06-24 MEDIUM 5.4 CVE-2026-57291 Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an att… Mitigation only Fix from $1,6002026-06-24 MEDIUM 5.4 CVE-2026-57294 A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect … Ec2 Fleet after 4.2.3.539.v8fedff2a_81c3 Fix from $1,6002026-06-24 HIGH 8.8 CVE-2026-7761 The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.1… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-9175 The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and… Mitigation only Fix from $1,6002026-06-24 HIGH 7.5 CVE-2026-9178 The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-8690 The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.… Mitigation only Fix from $1,6002026-06-24 MEDIUM 5.3 CVE-2026-9172 The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due t… Mitigation only Fix from $1,6002026-06-24 HIGH 8.8 CVE-2026-4297 The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is du… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-7617 The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin no… Mitigation only Fix from $1,6002026-06-24 MEDIUM 5.3 CVE-2026-8617 The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is … Mitigation only Fix from $1,6002026-06-24 MEDIUM 5.3 CVE-2026-12094 The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the… Mitigation only Fix from $1,6002026-06-24 CRITICAL 9.6 CVE-2026-11807 A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not v… Mitigation only Fix from $2,3002026-06-23