Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-34154 Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the dis… Discourse 2026.1.4 / 2026.3.1+ Fix from $1,6002026-05-19 HIGH 7.5 CVE-2026-47100 Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows … Mitigation only Fix from $1,9502026-05-19 HIGH 7.1 CVE-2026-30950 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.… Patch available Fix from $1,9502026-05-18 MEDIUM 5.4 CVE-2026-45244 Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call… Summarize 0.15.1+ Fix from $1,6002026-05-18 HIGH 7.1 CVE-2026-45242 Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write fil… Summarize 0.15.1+ Fix from $1,9502026-05-18 MEDIUM 6.1 CVE-2026-45243 Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages … Summarize 0.15.1+ Fix from $1,6002026-05-18 MEDIUM 6.5 CVE-2026-5163 Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated att… Mattermost Server 11.5.2+ Fix from $1,6002026-05-18 MEDIUM 6.5 CVE-2026-3117 Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin whic… Mattermost Server after 11.3.4 Fix from $1,6002026-05-18 MEDIUM 5.4 CVE-2026-1631 The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Fe… Mitigation only Fix from $1,6002026-05-18 MEDIUM 5.3 CVE-2026-8681 The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the… Mitigation only Fix from $1,6002026-05-16 MEDIUM 6.5 CVE-2026-45667 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, GET /api/v1/memories/ef is accessi… Open Webui 0.8.0+ Fix from $1,6002026-05-15 HIGH 7.1 CVE-2026-45350 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.6, there is a vulnerability in chat c… Open Webui 0.8.6+ Fix from $1,9502026-05-15 HIGH 7.1 CVE-2026-44569 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, there's an IDOR in the channels m… Open Webui 0.6.19+ Fix from $1,9502026-05-15 MEDIUM 6.5 CVE-2026-44571 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.6, in standard channels (i.e., channe… Open Webui 0.8.6+ Fix from $1,6002026-05-15 HIGH 7.2 CVE-2026-45395 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the tool update endpoint (POST /ap… Open Webui 0.9.5+ Fix from $1,9502026-05-15 MEDIUM 5.4 CVE-2026-44563 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /api/generate, /api/embed, /ap… Open Webui 0.9.0+ Fix from $1,6002026-05-15 HIGH 7.1 CVE-2026-45399 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user with low pr… Open Webui 0.9.0+ Fix from $1,9502026-05-15 HIGH 7.1 CVE-2026-44556 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the Ope… Open Webui 0.9.0+ Fix from $1,9502026-05-15 MEDIUM 5.4 CVE-2026-44558 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the channel router does not call f… Open Webui 0.9.0+ Fix from $1,6002026-05-15 MEDIUM 6.5 CVE-2026-44560 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the type: "file" (non-full-context… Open Webui 0.9.0+ Fix from $1,6002026-05-15 MEDIUM 6.5 CVE-2026-44562 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import end… Open Webui 0.9.0+ Fix from $1,6002026-05-15 MEDIUM 5.0 CVE-2026-44550 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = Con… Open Webui 0.9.0+ Fix from $1,6002026-05-15 HIGH 8.1 CVE-2026-44554 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/retrieval/process… Open Webui 0.9.0+ Fix from $1,9502026-05-15 HIGH 7.6 CVE-2026-44555 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI supports model composit… Open Webui 0.9.0+ Fix from $1,9502026-05-15 MEDIUM 5.4 CVE-2026-46365 phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authentic… Mitigation only Fix from $1,6002026-05-15 MEDIUM 5.3 CVE-2026-44718 Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, e… Mitigation only Fix from $1,6002026-05-15 MEDIUM 5.3 CVE-2026-44719 Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, collaborators.list,… Mitigation only Fix from $1,6002026-05-15 CRITICAL 10.0 CVE-2026-2031 An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remo… Mitigation only Fix from $2,3002026-05-15 MEDIUM 6.5 CVE-2026-4683 The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ro… Mitigation only Fix from $1,6002026-05-15 HIGH 8.1 CVE-2026-4094 The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability che… Mitigation only Fix from $1,9502026-05-15