Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.2 CVE-2026-73658 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() a… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-73305 Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking app… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.9 CVE-2026-73656 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/ba… No fix yet Fix from $5,7502026-08-13 HIGH 7.1 CVE-2026-72675 Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPE… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-72681 Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates … No fix yet Fix from $4,0002026-08-13 HIGH 8.1 CVE-2026-72665 Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Acce… No fix yet Fix from $4,9002026-08-13 HIGH 7.6 CVE-2026-72669 The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update … No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-72661 Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72664 Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functi… No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-59714 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite … No fix yet Fix from $4,9002026-08-13 CRITICAL 9.4 CVE-2026-73653 Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta… No fix yet Fix from $5,7502026-08-13 MEDIUM 5.9 CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of … No fix yet Fix from $4,0002026-08-13 CRITICAL 9.1 CVE-2026-58433 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting No fix yet Fix from $5,7502026-08-13 HIGH 7.5 CVE-2026-58434 Private Repository Metadata Remains Accessible After Access Revocation No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-58438 Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access No fix yet Fix from $4,9002026-08-13 MEDIUM 5.9 CVE-2026-57886 Cross-repository issue/comment attachment re-linking can expose private attachment content No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-73349 Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-73353 Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-73401 Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-73403 Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-66689 Unauthenticated Broken Access Control in Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-66693 Subscriber Broken Access Control in Motors <= 1.4.113 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-66660 Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-66469 Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-66461 Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-66464 Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-66466 Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= … No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-66454 Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 6.0 CVE-2026-66455 Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-66459 Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions. No fix yet Fix from $4,0002026-08-13