Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-33353 Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allo… Soft Serve 0.11.6+ Fix from $1,6002026-03-24 CRITICAL 9.1 CVE-2026-33768 Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query par… \@astrojs\/vercel 10.0.2+ Fix from $2,3002026-03-24 MEDIUM 5.3 CVE-2026-33160 Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, … Craft Cms 4.17.8 / 5.9.14+ Fix from $1,6002026-03-24 MEDIUM 6.5 CVE-2026-33162 Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp c… Craft Cms 5.9.14+ Fix from $1,6002026-03-24 MEDIUM 6.5 CVE-2026-33159 Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, … Craft Cms 4.17.8 / 5.9.14+ Fix from $1,6002026-03-24 HIGH 8.1 CVE-2026-33316 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled user… Vikunja 2.2.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-33484EPSS 6% Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{… Langflow 1.9.0+ Fix from $1,9502026-03-24 CRITICAL 9.1 CVE-2026-4283 The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This i… Mitigation only Fix from $2,3002026-03-24 MEDIUM 6.5 CVE-2026-3138 The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versi… Mitigation only Fix from $1,6002026-03-24 MEDIUM 5.4 CVE-2026-4056 The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the C… Mitigation only Fix from $1,6002026-03-24 MEDIUM 5.3 CVE-2026-33685 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.php` endpoint performs no auth… Avideo after 26.0 Fix from $1,6002026-03-23 MEDIUM 5.3 CVE-2026-33501 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/li… Avideo after 26.0 Fix from $1,6002026-03-23 HIGH 8.8 CVE-2026-4261 The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin al… Mitigation only Fix from $1,9502026-03-21 MEDIUM 5.3 CVE-2026-3651 The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. This is due to the plugi… Mitigation only Fix from $1,6002026-03-21 MEDIUM 5.3 CVE-2026-3645 The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.1. The save_c… Mitigation only Fix from $1,6002026-03-21 MEDIUM 5.3 CVE-2026-3570 The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing aut… Mitigation only Fix from $1,6002026-03-21 MEDIUM 5.3 CVE-2026-3506 The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9. This is due to the… Mitigation only Fix from $1,6002026-03-21 MEDIUM 5.3 CVE-2026-3335 The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/… Mitigation only Fix from $1,6002026-03-21 HIGH 8.8 CVE-2026-2941 The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'links… Mitigation only Fix from $1,9502026-03-21 MEDIUM 6.5 CVE-2026-2720 The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-… Mitigation only Fix from $1,6002026-03-21 MEDIUM 5.3 CVE-2026-3567 The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. T… Mitigation only Fix from $1,6002026-03-21 MEDIUM 5.3 CVE-2026-33425 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenticated users can determine whe… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-21 HIGH 7.5 CVE-2026-33427 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthenticated attacker can cause a… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,9502026-03-21 CRITICAL 9.9 CVE-2026-22172 OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password… Openclaw 2026.3.12+ Fix from $2,3002026-03-20 MEDIUM 5.3 CVE-2026-3550 The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. This is due to missing capabi… Mitigation only Fix from $1,6002026-03-20 CRITICAL 9.8 CVE-2026-4038 The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check… Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.1 CVE-2026-32817 Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the curre… Admidio 5.0.7+ Fix from $2,3002026-03-20 MEDIUM 6.5 CVE-2026-32818 Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does not verify whether the current … Admidio 5.0.7+ Fix from $1,6002026-03-19 HIGH 7.5 CVE-2026-29072 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed … Discourse 2026.1.2 / 2026.2.1+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-33304 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in… Openemr 8.0.0.2+ Fix from $1,6002026-03-19