Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.4 CVE-2026-33305 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in… Openemr 8.0.0.2+ Fix from $1,6002026-03-19 HIGH 8.8 CVE-2026-32622 SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulner… Sqlbot 1.6.0+ Fix from $1,9502026-03-19 MEDIUM 5.3 CVE-2026-27454 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X by… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-26939 Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (ho… Kibana 8.19.12 / 9.2.6+ Fix from $1,6002026-03-19 HIGH 7.5 CVE-2026-25443 Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers a… Mitigation only Fix from $1,9502026-03-19 MEDIUM 5.3 CVE-2026-3475 The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all versions up to and including 1.1… Mitigation only Fix from $1,6002026-03-19 HIGH 7.5 CVE-2026-25312 Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Cont… Mitigation only Fix from $1,9502026-03-19 MEDIUM 6.3 CVE-2026-27091 Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This… Mitigation only Fix from $1,6002026-03-19 MEDIUM 5.3 CVE-2026-28070 Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… Mitigation only Fix from $1,6002026-03-19 MEDIUM 5.3 CVE-2026-2559 The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oaut… Mitigation only Fix from $1,6002026-03-18 HIGH 8.2 CVE-2026-2992 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on th… Mitigation only Fix from $1,9502026-03-18 MEDIUM 5.3 CVE-2026-32565 Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrectly Configured Access Control… Mitigation only Fix from $1,6002026-03-18 MEDIUM 5.4 CVE-2026-1217 The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_… Mitigation only Fix from $1,6002026-03-18 HIGH 8.7 CVE-2026-32268 The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, u… Patch available Fix from $1,9502026-03-18 MEDIUM 5.3 CVE-2026-1926 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `w… Mitigation only Fix from $1,6002026-03-18 HIGH 8.3 CVE-2026-4064 Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid t… Powershell Universal 2026.1.4+ Fix from $1,9502026-03-17 HIGH 8.1 CVE-2026-30911 Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows… Airflow 3.1.8+ Fix from $1,9502026-03-17 MEDIUM 5.3 CVE-2026-32586 Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectly Configured Access Control S… Mitigation only Fix from $1,6002026-03-17 MEDIUM 5.3 CVE-2026-2373 The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up… Mitigation only Fix from $1,6002026-03-17 MEDIUM 5.3 CVE-2026-32583 Missing Authorization vulnerability in Webnus Inc. Modern Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… Mitigation only Fix from $1,6002026-03-16 MEDIUM 5.4 CVE-2026-32587 Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This… Mitigation only Fix from $1,6002026-03-16 MEDIUM 5.3 CVE-2026-2233 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unautho… Mitigation only Fix from $1,6002026-03-16 HIGH 8.3 CVE-2026-25083 GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared… Mitigation only Fix from $1,9502026-03-16 MEDIUM 5.3 CVE-2026-1870 The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a m… Mitigation only Fix from $1,6002026-03-16 HIGH 7.5 CVE-2026-3045 The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all ve… Mitigation only Fix from $1,9502026-03-13 MEDIUM 5.3 CVE-2026-32487 Missing Authorization vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Exploiting Incorrectly Configured Access Control Secu… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.3 CVE-2026-32543 Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting Incorrectly Configured Access C… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.3 CVE-2026-32486 Missing Authorization vulnerability in wptravelengine Travel Booking travel-booking allows Exploiting Incorrectly Configured Access Control Security … No fix yet Fix from $1,6002026-03-13 MEDIUM 5.3 CVE-2026-32457 Missing Authorization vulnerability in Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce advanced-product-fields-for-woocommerc… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32451 Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,6002026-03-13