Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.5 CVE-2026-8547 Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the re… Chrome 148.0.7778.168+ Fix from $1,9502026-05-14 CRITICAL 9.4 CVE-2026-44592 Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone … Mitigation only Fix from $2,3002026-05-14 HIGH 7.2 CVE-2026-45371 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated… Mitigation only Fix from $1,9502026-05-14 CRITICAL 9.8 CVE-2026-41315 mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to… Mdserver Web after 0.18.4 Fix from $2,3002026-05-14 CRITICAL 9.6 CVE-2026-44482 soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an… Mitigation only Fix from $2,3002026-05-14 MEDIUM 5.4 CVE-2026-6472 Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, inc… PostgreSQL 14.23 / 15.18+ Fix from $1,6002026-05-14 HIGH 7.5 CVE-2026-4029 The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. Thi… Mitigation only Fix from $1,9502026-05-14 HIGH 8.1 CVE-2026-4030 The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and incl… Mitigation only Fix from $1,9502026-05-14 HIGH 7.5 CVE-2026-4031 The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due… Mitigation only Fix from $1,9502026-05-14 CRITICAL 9.1 CVE-2026-6512 The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin … Mitigation only Fix from $2,3002026-05-14 MEDIUM 5.3 CVE-2026-6145 The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is d… Mitigation only Fix from $1,6002026-05-14 CRITICAL 9.8 CVE-2026-6510 The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. … Mitigation only Fix from $2,3002026-05-14 HIGH 8.8 CVE-2026-6506 The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infused… Mitigation only Fix from $1,9502026-05-14 MEDIUM 5.4 CVE-2026-3829 The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized mod… Mitigation only Fix from $1,6002026-05-14 CRITICAL 9.9 CVE-2026-44442 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks… Erpnext 16.9.1+ Fix from $2,3002026-05-13 MEDIUM 6.5 CVE-2026-44448 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper author… Erpnext 15.102.0 / 16.11.0+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-28380 Any Editor could delete any snapshot, even if they have no access to read or write them. Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 HIGH 7.8 CVE-2026-0246 A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrati… Prisma Access Agent 26.2.1+ Fix from $1,9502026-05-13 HIGH 7.1 CVE-2026-4609 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… Mitigation only Fix from $1,9502026-05-13 MEDIUM 5.3 CVE-2026-2515 The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… Mitigation only Fix from $1,6002026-05-13 MEDIUM 5.4 CVE-2026-7051 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,… Mitigation only Fix from $1,6002026-05-13 MEDIUM 5.3 CVE-2025-14755 The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR) in a… Mitigation only Fix from $1,6002026-05-13 HIGH 7.1 CVE-2026-5371 The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access an… Mitigation only Fix from $1,9502026-05-12 HIGH 7.1 CVE-2026-44012 Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and re… Patch available Fix from $1,9502026-05-12 HIGH 7.1 CVE-2026-44010 Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elem… Patch available Fix from $1,9502026-05-12 HIGH 8.3 CVE-2026-35438 Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. Windows Admin Center 2511+ Fix from $1,9502026-05-12 MEDIUM 5.3 CVE-2026-31245 The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unau… Mem0 Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.5 CVE-2026-31241 The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows un… Mem0 Mitigation only Fix from $1,6002026-05-12 CRITICAL 9.1 CVE-2026-31242 The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoin… Mem0 Mitigation only Fix from $2,3002026-05-12 MEDIUM 6.5 CVE-2026-31243 The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DEL… Mem0 Mitigation only Fix from $1,6002026-05-12