Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-72900 Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. No fix yet Fix from $4,0002026-08-10 CRITICAL 9.6 CVE-2026-72737 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs … No fix yet Fix from $5,7502026-08-10 MEDIUM 5.3 CVE-2026-72723 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_men… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.3 CVE-2026-47754 Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions conta… No fix yet Fix from $5,7502026-08-10 MEDIUM 6.9 CVE-2026-72759 In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record… No fix yet Fix from $4,0002026-08-10 MEDIUM 5.8 CVE-2026-71959 Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing… No fix yet Fix from $4,0002026-08-10 HIGH 7.5 CVE-2026-72692 A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline… No fix yet Fix from $4,9002026-08-10 MEDIUM 6.5 CVE-2026-19404 A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization … No fix yet Fix from $4,0002026-08-10 MEDIUM 5.3 CVE-2026-17021 The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does… No fix yet Fix from $4,0002026-08-10 HIGH 8.1 CVE-2026-18030 The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one… No fix yet Fix from $4,9002026-08-10 MEDIUM 5.4 CVE-2026-14941 The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX act… No fix yet Fix from $4,0002026-08-10 MEDIUM 5.3 CVE-2026-15237 The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payme… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.3 CVE-2026-19350 A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component Ta… No fix yet Fix from $4,0002026-08-09 MEDIUM 6.5 CVE-2026-19345 A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manip… No fix yet Fix from $4,0002026-08-09 MEDIUM 6.5 CVE-2026-18603 The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding … No fix yet Fix from $4,0002026-08-09 MEDIUM 6.5 CVE-2026-18037 The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and… No fix yet Fix from $4,0002026-08-09 MEDIUM 6.5 CVE-2026-16992 The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that r… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-16608 The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the… No fix yet Fix from $1,6002026-08-08 MEDIUM 6.5 CVE-2026-47127 Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/sub… No fix yet Fix from $1,6002026-08-07 HIGH 8.8 CVE-2026-48169 PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break wo… No fix yet Fix from $1,9502026-08-07 MEDIUM 5.7 CVE-2026-64676 Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the … No fix yet Fix from $1,6002026-08-07 HIGH 7.1 CVE-2026-66060 Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links … No fix yet Fix from $1,9502026-08-07 HIGH 7.1 CVE-2026-66061 Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag lin… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.8 CVE-2026-19017 Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2026-66058 Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is poss… No fix yet Fix from $1,6002026-08-07 HIGH 8.9 CVE-2026-17601 A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader per… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.9 CVE-2026-54201 Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attacke… No fix yet Fix from $1,6002026-08-07 HIGH 7.5 CVE-2026-16041 The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route,… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.5 CVE-2026-15359 The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers… No fix yet Fix from $1,6002026-08-07 CRITICAL 9.1 CVE-2026-16038 The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its… No fix yet Fix from $2,3002026-08-07