Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-24004 Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow una… Fleet 4.80.1+ Fix from $1,6002026-02-26 MEDIUM 6.5 CVE-2026-27954 Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints … Live Helper Chat after 4.52 Fix from $1,6002026-02-26 MEDIUM 6.5 CVE-2026-27946 ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability a… Zitadel 3.4.7 / 4.11.0+ Fix from $1,6002026-02-26 HIGH 8.1 CVE-2026-25164 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the REST API route t… Openemr 8.0.0+ Fix from $1,9502026-02-25 MEDIUM 5.3 CVE-2026-28193 In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint Youtrack 2025.3.121962+ Fix from $1,6002026-02-25 MEDIUM 5.5 CVE-2026-26104 A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The… Enterprise Linux Mitigation only Fix from $1,6002026-02-25 HIGH 7.1 CVE-2026-26103 A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper aut… Enterprise Linux Mitigation only Fix from $1,9502026-02-25 HIGH 7.5 CVE-2026-1916 The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks … Mitigation only Fix from $1,9502026-02-25 HIGH 8.1 CVE-2026-27608 Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint… Parse Dashboard Mitigation only Fix from $1,9502026-02-25 MEDIUM 6.5 CVE-2026-25124 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the OpenEMR applicat… Openemr 8.0.0+ Fix from $1,6002026-02-25 HIGH 8.8 CVE-2026-25131 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Cont… Openemr 8.0.0+ Fix from $1,9502026-02-25 HIGH 8.8 CVE-2026-22765 Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access co… Wyse Management Suite 5.5+ Fix from $1,9502026-02-24 HIGH 8.2 CVE-2026-27468 Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versio… Mastodon 4.4.14 / 4.5.7+ Fix from $1,9502026-02-24 MEDIUM 6.5 CVE-2025-14339 The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unau… Mitigation only Fix from $1,6002026-02-21 CRITICAL 9.1 CVE-2026-27471 ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack… Erpnext 15.98.1 / 16.6.1+ Fix from $2,3002026-02-21 CRITICAL 9.8 CVE-2026-2038 GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication… Archiver Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-2039 GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authenticatio… Archiver Mitigation only Fix from $2,3002026-02-20 MEDIUM 5.0 CVE-2026-27111 Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model includes a promote verb -- a non-… Kargo 1.9.3+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-24946 Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Inc… Mitigation only Fix from $1,6002026-02-20 HIGH 7.5 CVE-2026-24941 Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Level… Mitigation only Fix from $1,9502026-02-20 MEDIUM 6.5 CVE-2026-24944 Missing Authorization vulnerability in weDevs Subscribe2 subscribe2 allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… Mitigation only Fix from $1,6002026-02-20 HIGH 7.5 CVE-2026-22351 Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectly Configured Access Control S… Mitigation only Fix from $1,9502026-02-20 MEDIUM 6.5 CVE-2026-22350 Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Exploiting… Mitigation only Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2025-69388 Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access Control Security Levels.This… Mitigation only Fix from $1,6002026-02-20 HIGH 7.5 CVE-2025-69393 Missing Authorization vulnerability in Jthemes Exzo exzo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects E… Mitigation only Fix from $1,9502026-02-20 MEDIUM 6.5 CVE-2025-69385 Missing Authorization vulnerability in AgniHD Cartify - WooCommerce Gutenberg WordPress Theme cartify allows Exploiting Incorrectly Configured Access… Mitigation only Fix from $1,6002026-02-20 HIGH 7.1 CVE-2025-69381 Missing Authorization vulnerability in vanquish WooCommerce Bulk Product Editor woocommerce-quick-product-editor allows Exploiting Incorrectly Config… Mitigation only Fix from $1,9502026-02-20 HIGH 7.5 CVE-2025-69303 Missing Authorization vulnerability in modeltheme ModelTheme Framework modeltheme-framework allows Exploiting Incorrectly Configured Access Control S… Mitigation only Fix from $1,9502026-02-20 HIGH 7.5 CVE-2025-69297 Missing Authorization vulnerability in GhostPool Aardvark Plugin aardvark-plugin allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,9502026-02-20 HIGH 7.5 CVE-2025-69298 Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec… Mitigation only Fix from $1,9502026-02-20