Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.3 CVE-2026-19010 A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the c… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-16290 The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the hand… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-16734 The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by t… No fix yet Fix from $1,9502026-08-06 HIGH 8.8 CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in … No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-71316 Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can… No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-70617 Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbi… No fix yet Fix from $1,9502026-08-05 CRITICAL 10.0 CVE-2026-48168 PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection b… No fix yet Fix from $2,3002026-08-05 MEDIUM 6.5 CVE-2026-70439 Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-17613 Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files o… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-7529 The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to ev… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-7456 The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` … No fix yet Fix from $1,6002026-08-05 HIGH 8.2 CVE-2026-71264 WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike the /edit endpoint which expl… No fix yet Fix from $1,9502026-08-05 HIGH 8.2 CVE-2026-71252 toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related a… No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `si… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-7726 The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::tem… No fix yet Fix from $1,6002026-08-05 HIGH 8.2 CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-6639 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… No fix yet Fix from $1,9502026-08-05 HIGH 7.3 CVE-2026-6079 The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-5581 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-4431 The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_pos… No fix yet Fix from $2,3002026-08-05 HIGH 8.1 CVE-2026-54418 Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on … No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-12000 The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the Word… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-16605 The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allow… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-16561 The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated u… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-7753 The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cos… No fix yet Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-8761 The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorizat… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-70619 Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embeddi… No fix yet Fix from $1,9502026-08-04 HIGH 8.1 CVE-2026-70494 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handl… No fix yet Fix from $1,9502026-08-04 MEDIUM 5.3 CVE-2026-70487 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted … No fix yet Fix from $1,6002026-08-04 HIGH 7.1 CVE-2026-13227 An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API … No fix yet Fix from $1,9502026-08-04