Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-11907 The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not prop… No fix yet Fix from $1,6002026-08-07 CRITICAL 9.8 CVE-2026-14365 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu… No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-65667 Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. Teams No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-62830 Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. Azure Sre Agent No fix yet Fix from $2,3002026-08-07 HIGH 7.5 CVE-2026-70636 Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh e… No fix yet Fix from $1,9502026-08-06 HIGH 7.6 CVE-2026-67621 Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document sto… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-64662 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view con… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.8 CVE-2026-48085 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provision… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.4 CVE-2026-48088 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /… No fix yet Fix from $2,3002026-08-06 MEDIUM 5.3 CVE-2026-48077 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler a… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-48075 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunne… No fix yet Fix from $1,6002026-08-06 HIGH 7.1 CVE-2026-47765 Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate … No fix yet Fix from $1,9502026-08-06 MEDIUM 6.0 CVE-2026-45415 Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_censu… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-13399 The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unau… No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-18277 Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to gran… Escriptorium No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-66712 Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. No fix yet Fix from $1,9502026-08-06 HIGH 8.2 CVE-2026-66708 Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-66699 Custom role Broken Access Control in Dokan <= 5.0.10 versions. No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-66701 Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. No fix yet Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-66452 Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions. No fix yet Fix from $1,6002026-08-06 HIGH 7.1 CVE-2026-66470 Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-65554 Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.3 CVE-2026-65541 Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-65504 Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-32548 Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-28140 Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-25403 Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. No fix yet Fix from $1,6002026-08-06 CRITICAL 9.8 CVE-2026-28005 Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. No fix yet Fix from $2,3002026-08-06 HIGH 7.5 CVE-2026-65551 Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-11983 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 du… No fix yet Fix from $1,6002026-08-06