Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-34261 Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to cer… Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2026-27677 Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could update and delete child entities… Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2026-27678 Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker could update and delete child… Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2026-27679 Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete chil… Manage Reference Structures Mitigation only Fix from $1,6002026-04-14 HIGH 8.8 CVE-2026-6109 A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environ… Metagpt after 0.8.1 Fix from $1,9502026-04-12 MEDIUM 5.4 CVE-2026-3358 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course enrollment in all versions up … Mitigation only Fix from $1,6002026-04-11 MEDIUM 6.5 CVE-2026-40185 TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo management routes. This vulner… Trek after 2.7.1 Fix from $1,6002026-04-10 CRITICAL 9.8 CVE-2026-40189 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for direct… Goshs 2.0.0+ Fix from $2,3002026-04-10 MEDIUM 6.5 CVE-2026-33708 Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email,… Chamilo Lms 1.11.38+ Fix from $1,6002026-04-10 MEDIUM 6.5 CVE-2026-33141 Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endp… Chamilo Lms after 1.11.38 Fix from $1,6002026-04-10 HIGH 8.1 CVE-2026-35660 OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint that allows callers with operato… Openclaw 2026.3.23+ Fix from $1,9502026-04-10 MEDIUM 5.4 CVE-2026-35620 OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows … Openclaw 2026.3.24+ Fix from $1,6002026-04-10 MEDIUM 6.5 CVE-2026-35621 OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validate gateway client scopes for i… Openclaw 2026.3.24+ Fix from $1,6002026-04-10 HIGH 7.1 CVE-2026-4162 The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not p… Mitigation only Fix from $1,9502026-04-10 HIGH 7.5 CVE-2026-3360 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to,… Mitigation only Fix from $1,9502026-04-10 HIGH 7.5 CVE-2026-40117 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesyst… Praisonaiagents 1.5.128+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-35631 OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attacker… Openclaw 2026.3.22+ Fix from $1,6002026-04-09 HIGH 8.8 CVE-2026-33785 A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to … Junos Mitigation only Fix from $1,9502026-04-09 MEDIUM 5.5 CVE-2026-33776 A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read se… Junos 22.4 / 23.2+ Fix from $1,6002026-04-09 HIGH 8.8 CVE-2026-35063 OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other… Openplc V3 Firmware Mitigation only Fix from $1,9502026-04-09 CRITICAL 9.1 CVE-2026-34184 AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and ev… Control System 9.8.5+ Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-1830EPSS 8% The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insuffic… Mitigation only Fix from $2,3002026-04-09 MEDIUM 5.4 CVE-2026-4124 The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The wp_ajax_ziggeo_ajax handler … Mitigation only Fix from $1,6002026-04-09 HIGH 8.8 CVE-2026-4326 The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to… Mitigation only Fix from $1,9502026-04-09 CRITICAL 9.1 CVE-2026-39429 kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cach… Kcp 0.29.3 / 0.30.3+ Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-33229 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly p… Xwiki 17.4.8 / 17.10.1+ Fix from $2,3002026-04-08 MEDIUM 5.3 CVE-2026-39713 Missing Authorization vulnerability in mailercloud Mailercloud – Integrate webforms and synchronize website contacts mailercloud-integrate-webforms-s… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-39714 Missing Authorization vulnerability in G5Theme G5Plus April g5plus-april allows Exploiting Incorrectly Configured Access Control Security Levels.This… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-39715 Missing Authorization vulnerability in AnyTrack AnyTrack Affiliate Link Manager anytrack-affiliate-link-manager allows Exploiting Incorrectly Configu… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-39716 Missing Authorization vulnerability in CKThemes Flipmart flipmart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue … No fix yet Fix from $1,6002026-04-08