Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-3143 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data… Mitigation only Fix from $1,6002026-05-01 HIGH 7.5 CVE-2026-40601 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Char… Mitigation only Fix from $1,9502026-04-30 MEDIUM 5.3 CVE-2026-42642 Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec… Mitigation only Fix from $1,6002026-04-29 MEDIUM 5.3 CVE-2026-4019 The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 T… Mitigation only Fix from $1,6002026-04-29 MEDIUM 6.5 CVE-2026-42412 Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue a… Mitigation only Fix from $1,6002026-04-29 HIGH 7.3 CVE-2026-42377 Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This … Mitigation only Fix from $1,9502026-04-29 HIGH 8.2 CVE-2026-41394 OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive operator runtime writ… Openclaw 2026.3.31+ Fix from $1,9502026-04-28 MEDIUM 5.4 CVE-2026-41382 OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers to bypass channel and member … Openclaw 2026.3.31+ Fix from $1,6002026-04-28 HIGH 8.8 CVE-2026-41378 OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests wi… Openclaw 2026.3.31+ Fix from $1,9502026-04-28 MEDIUM 6.5 CVE-2026-6706 Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content fr… Devolutions Server 2025.3.19.0 / 2026.1.15.0+ Fix from $1,6002026-04-28 HIGH 8.2 CVE-2026-5944 An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passth… Intersight Device Connector after 7.5.0 Fix from $1,9502026-04-28 CRITICAL 9.1 CVE-2026-40976 In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be v… Spring Boot 4.0.6+ Fix from $2,3002026-04-28 MEDIUM 6.5 CVE-2026-41464 ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users … Mitigation only Fix from $1,6002026-04-27 HIGH 7.8 CVE-2026-41477 Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with … Deskflow after 1.26.0.161 Fix from $1,9502026-04-24 MEDIUM 5.3 CVE-2026-3569 The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-pr… Mitigation only Fix from $1,6002026-04-24 MEDIUM 5.3 CVE-2026-5347 The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of… Mitigation only Fix from $1,6002026-04-24 MEDIUM 5.3 CVE-2026-5488 The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and includi… Mitigation only Fix from $1,6002026-04-24 HIGH 8.8 CVE-2026-33318 Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on se… Actual 26.4.0+ Fix from $1,9502026-04-24 HIGH 8.1 CVE-2026-40623 A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without suff… X3500 Firmware Mitigation only Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-41352 OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mec… Openclaw 2026.3.31+ Fix from $1,9502026-04-23 HIGH 8.8 CVE-2026-41349 OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patc… Openclaw 2026.3.28+ Fix from $1,9502026-04-23 HIGH 7.5 CVE-2026-41266 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes … Flowise 3.1.0+ Fix from $1,9502026-04-23 HIGH 7.2 CVE-2026-5464 The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugi… Mitigation only Fix from $1,9502026-04-23 CRITICAL 10.0 CVE-2026-41679 Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated a… Paperclipai 2026.416.0+ Fix from $2,3002026-04-23 HIGH 8.3 CVE-2026-41454 WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to per… Patch available Fix from $1,9502026-04-22 HIGH 8.3 CVE-2026-40937 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src… Rustfs Mitigation only Fix from $1,9502026-04-22 CRITICAL 9.8 CVE-2026-6235 The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up … Mitigation only Fix from $2,3002026-04-22 MEDIUM 5.3 CVE-2026-4117 The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is due to a missing capability c… Mitigation only Fix from $1,6002026-04-22 CRITICAL 9.1 CVE-2026-4119 The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin… Mitigation only Fix from $2,3002026-04-22 MEDIUM 6.5 CVE-2026-6834 The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database conten… Mitigation only Fix from $1,6002026-04-22