Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-32332 Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.3 CVE-2026-32334 Missing Authorization vulnerability in raratheme JobScout jobscout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.3 CVE-2026-31915 Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.3 CVE-2026-31916 Missing Authorization vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Exploiting Incorrectly Configured Access Contro… Mitigation only Fix from $1,6002026-03-13 HIGH 7.5 CVE-2026-2890 The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the … Mitigation only Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-22182 wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by… Wpdiscuz 7.6.47+ Fix from $1,9502026-03-13 MEDIUM 5.3 CVE-2026-32230 Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration? endpoint in server/routers/a… Uptime Kuma 2.2.0+ Fix from $1,6002026-03-12 HIGH 7.5 CVE-2026-28254 A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitiv… Tracer Sc Firmware 6.3.2310+ Fix from $1,9502026-03-12 MEDIUM 6.5 CVE-2026-21668 A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. Veeam Backup \& Replication 12.3.2.4465+ Fix from $1,6002026-03-12 MEDIUM 6.3 CVE-2026-3977 A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. T… Patch available Fix from $1,6002026-03-12 HIGH 7.7 CVE-2026-32131 ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, whi… Zitadel 3.4.8 / 4.12.2+ Fix from $1,9502026-03-11 HIGH 8.1 CVE-2026-32126 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condit… Openemr 8.0.0.1+ Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2026-29515 MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log … Fileexplorer Mitigation only Fix from $2,3002026-03-11 MEDIUM 6.5 CVE-2026-1781 The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.11.1. This is … Patch available Fix from $1,6002026-03-11 HIGH 7.2 CVE-2026-31834 Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under ce… Umbraco Cms 16.5.1 / 17.2.2+ Fix from $1,9502026-03-10 MEDIUM 5.3 CVE-2026-31821 Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does not verify cart ownership. An … Sylius 2.0.16 / 2.1.12+ Fix from $1,6002026-03-10 CRITICAL 9.1 CVE-2026-31800 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.12 and 8.6.25, the _Grap… Parse Server 8.6.25 / 9.5.2+ Fix from $2,3002026-03-10 HIGH 8.1 CVE-2026-26741 PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while… Px4 Drone Autopilot 1.16.0+ Fix from $1,9502026-03-10 HIGH 8.1 CVE-2026-26742 PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applie… Px4 Drone Autopilot 1.16.0+ Fix from $1,9502026-03-10 MEDIUM 5.0 CVE-2026-30959 OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a… Oneuptime 10.0.21+ Fix from $1,6002026-03-10 CRITICAL 9.8 CVE-2026-30968 Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1… Coral Server 1.1.0+ Fix from $2,3002026-03-10 CRITICAL 9.1 CVE-2026-30970 Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1… Coral Server 1.1.0+ Fix from $2,3002026-03-10 CRITICAL 9.9 CVE-2026-30956 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isol… Oneuptime 10.0.21+ Fix from $2,3002026-03-10 HIGH 8.6 CVE-2026-30920 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled sta… Oneuptime 10.0.19+ Fix from $1,9502026-03-10 MEDIUM 5.3 CVE-2026-30885 WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user with… Avideo 25.0+ Fix from $1,6002026-03-10 MEDIUM 5.9 CVE-2026-27686 Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an aff… Mitigation only Fix from $1,6002026-03-10 MEDIUM 5.8 CVE-2026-27687 Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belo… Mitigation only Fix from $1,6002026-03-10 MEDIUM 5.0 CVE-2026-27688 Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-03-10 MEDIUM 5.0 CVE-2026-24313 SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allow… Mitigation only Fix from $1,6002026-03-10 MEDIUM 6.4 CVE-2026-24309 Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function modul… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-03-10