Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2026-5228 Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly C… Mitigation only Fix from $1,9502026-06-04 MEDIUM 6.3 CVE-2026-10815 A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown … Mitigation only Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-4881 In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level ch… Octopus Server 2025.4.10545 / 2026.1.11313+ Fix from $1,6002026-06-04 HIGH 7.5 CVE-2026-10737 The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file functi… Mitigation only Fix from $1,9502026-06-04 HIGH 7.0 CVE-2026-44281 GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user wit… Mitigation only Fix from $1,9502026-06-03 HIGH 7.0 CVE-2026-42317 GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete a… Mitigation only Fix from $1,9502026-06-03 HIGH 7.0 CVE-2026-42318 GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with… Mitigation only Fix from $1,9502026-06-03 MEDIUM 5.9 CVE-2026-42320 GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arb… Mitigation only Fix from $1,6002026-06-03 HIGH 7.1 CVE-2026-31942 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Referenc… Librechat 0.8.3+ Fix from $1,9502026-06-02 MEDIUM 5.3 CVE-2026-40571 NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wal… Mitigation only Fix from $1,6002026-06-02 MEDIUM 5.3 CVE-2026-35443 NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the c… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.9 CVE-2026-40314 NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall… Mitigation only Fix from $1,6002026-06-02 MEDIUM 5.4 CVE-2026-49782 Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. … No fix yet Fix from $1,6002026-06-02 MEDIUM 5.4 CVE-2026-27351 Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue … Mitigation only Fix from $1,6002026-06-02 HIGH 7.5 CVE-2026-42669 Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventP… Mitigation only Fix from $1,9502026-06-02 HIGH 7.5 CVE-2026-42670 Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Acce… Mitigation only Fix from $1,9502026-06-02 HIGH 8.8 CVE-2025-53345 Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core. This issue affect… Mitigation only Fix from $1,9502026-06-02 MEDIUM 6.5 CVE-2025-52766 Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. Thi… No fix yet Fix from $1,6002026-06-02 MEDIUM 5.3 CVE-2025-53302 Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constrained by ACLs. This issue affect… Mitigation only Fix from $1,6002026-06-02 HIGH 7.8 CVE-2025-26418 In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a manage… Android Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.4 CVE-2026-45285 Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a … Nextcloud Server 32.0.9 / 33.0.3+ Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-45267 Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form… Patch available Fix from $1,6002026-06-01 HIGH 7.3 CVE-2026-42675 Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue af… Mitigation only Fix from $1,9502026-06-01 HIGH 7.5 CVE-2026-42677 Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. Thi… Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-42671 Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affect… No fix yet Fix from $1,6002026-06-01 CRITICAL 9.1 CVE-2026-42682 Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue aff… Mitigation only Fix from $2,3002026-06-01 HIGH 8.8 CVE-2026-40543 SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and ret… Mitigation only Fix from $1,9502026-06-01 MEDIUM 5.3 CVE-2026-8382 The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due… Mitigation only Fix from $1,6002026-05-31 MEDIUM 6.5 CVE-2026-49385 In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts Youtrack 2026.1.13570+ Fix from $1,6002026-05-29 HIGH 7.6 CVE-2026-49374 In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters Teamcity 2026.1+ Fix from $1,9502026-05-29