Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-47745 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and… Patch available Fix from $1,6002026-05-29 HIGH 8.8 CVE-2026-49367 In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account Intellij Idea 2026.1.1+ Fix from $1,9502026-05-29 HIGH 8.1 CVE-2026-47740 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were call… Patch available Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2026-47742 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping… Patch available Fix from $1,6002026-05-29 HIGH 8.8 CVE-2026-47125 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/varia… Mitigation only Fix from $1,9502026-05-29 CRITICAL 9.9 CVE-2026-45632 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. … Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45625 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endp… Mitigation only Fix from $2,3002026-05-29 HIGH 8.0 CVE-2026-35630 OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver i… Openclaw 2026.5.18+ Fix from $1,9502026-05-29 HIGH 8.3 CVE-2026-32905 OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat sende… Openclaw 2026.5.4+ Fix from $1,9502026-05-29 HIGH 7.5 CVE-2018-25391 HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sendi… No fix yet Fix from $1,9502026-05-29 CRITICAL 9.1 CVE-2026-4290 The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoin… Mitigation only Fix from $2,3002026-05-29 MEDIUM 5.3 CVE-2025-12714 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… Mitigation only Fix from $1,6002026-05-29 MEDIUM 6.5 CVE-2026-44884 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber… Portainer 2.33.8 / 2.39.1+ Fix from $1,6002026-05-28 HIGH 8.8 CVE-2026-44848 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber… Portainer 2.33.8 / 2.39.2+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-44849 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber… Portainer 2.33.8 / 2.39.1+ Fix from $1,9502026-05-28 HIGH 7.2 CVE-2026-42071 Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility fun… Patch available Fix from $1,9502026-05-28 MEDIUM 5.4 CVE-2026-44794 Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericF… Nautobot 2.4.33 / 3.1.2+ Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-6937 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all ver… Mitigation only Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-7552 The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin no… Mitigation only Fix from $1,6002026-05-28 HIGH 8.8 CVE-2026-7802 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due… Mitigation only Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-46414 Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control … Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-48151 Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generi… Mitigation only Fix from $1,9502026-05-27 CRITICAL 9.9 CVE-2026-46425 Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCI… Mitigation only Fix from $2,3002026-05-27 HIGH 8.8 CVE-2026-45717 Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/… Mitigation only Fix from $1,9502026-05-27 CRITICAL 9.4 CVE-2026-44326 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound … Free5gc 4.2.2+ Fix from $2,3002026-05-27 CRITICAL 10.0 CVE-2026-44327 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2… Free5gc 4.2.2+ Fix from $2,3002026-05-27 HIGH 8.2 CVE-2026-44328 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound … Free5gc 4.2.2+ Fix from $1,9502026-05-27 CRITICAL 10.0 CVE-2026-44329 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/b… Free5gc 4.2.2+ Fix from $2,3002026-05-27 HIGH 7.3 CVE-2026-44320 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound O… Free5gc 4.2.2+ Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-44321 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound … Free5gc 4.2.2+ Fix from $1,9502026-05-27