Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Junos Os Evolved HIGH 7.8
CVE-2025-52954

A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-p…

Fix: 22.2+
Fix from $1,950 2025-07-11
Security Director CRITICAL 9.6
CVE-2025-52950

A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with m…

Mitigation only
Fix from $2,300 2025-07-11
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible MEDIUM 6.5
CVE-2025-3780

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized m…

Fix: 6.7.17+
Fix from $1,600 2025-07-09
Windows 10 1809 HIGH 8.8
CVE-2025-49723

Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.

Fix: 10.0.17763.7558 / 10.0.19044.6093+
Fix from $1,950 2025-07-08
Unclassified MEDIUM 5.3
CVE-2025-5957

The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a mi…

Mitigation only
Fix from $1,600 2025-07-08
Unclassified HIGH 7.7
CVE-2025-42952

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, poten…

Mitigation only
Fix from $1,950 2025-07-08
Unclassified HIGH 8.1
CVE-2025-42953

SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. …

Mitigation only
Fix from $1,950 2025-07-08
Unclassified CRITICAL 9.1
CVE-2025-53495

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki…

Mitigation only
Fix from $2,300 2025-07-07
Unclassified CRITICAL 9.1
CVE-2025-53499

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki…

Mitigation only
Fix from $2,300 2025-07-07
Online Movie Ticket Booking System MEDIUM 5.4
CVE-2025-7133

A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manip…

No fix yet
Fix from $1,600 2025-07-07
Unclassified HIGH 7.5
CVE-2025-53485

SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related t…

Mitigation only
Fix from $1,950 2025-07-04
Unclassified HIGH 8.1
CVE-2025-52813

Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mo…

Mitigation only
Fix from $1,950 2025-07-04
Unclassified MEDIUM 6.5
CVE-2025-50039

Missing Authorization vulnerability in vgwort VG WORT METIS vgw-metis allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Mitigation only
Fix from $1,600 2025-07-04
Unclassified MEDIUM 6.5
CVE-2025-50032

Missing Authorization vulnerability in Paytiko - Payment Orchestration Platform Paytiko for WooCommerce paytiko allows Exploiting Incorrectly Configu…

Mitigation only
Fix from $1,600 2025-07-04
Unclassified MEDIUM 6.5
CVE-2025-49431

Missing Authorization vulnerability in Gnuget MF Plus WPML mf-plus-wpml allows Exploiting Incorrectly Configured Access Control Security Levels.This …

Mitigation only
Fix from $1,600 2025-07-04
Unclassified MEDIUM 6.5
CVE-2025-47634

Missing Authorization vulnerability in Keylor Mendoza WC Pickup Store wc-pickup-store allows Exploiting Incorrectly Configured Access Control Securit…

Mitigation only
Fix from $1,600 2025-07-04
Unclassified MEDIUM 6.3
CVE-2025-47565

Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

Mitigation only
Fix from $1,600 2025-07-04
Unclassified MEDIUM 5.3
CVE-2025-30929

Missing Authorization vulnerability in amazewp fluXtore fluxtore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

Mitigation only
Fix from $1,600 2025-07-04
Unclassified MEDIUM 5.3
CVE-2025-29012

Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on CF7-mailchimp-addon allows Exploiting Incorrectly Configured Access Contro…

Mitigation only
Fix from $1,600 2025-07-04
Unclassified MEDIUM 5.3
CVE-2025-24757

Missing Authorization vulnerability in AndonDesign uDesign udesign.This issue affects uDesign: from n/a through <= 4.11.2.

Mitigation only
Fix from $1,600 2025-07-04
Unclassified MEDIUM 5.3
CVE-2025-24748

Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.

No fix yet
Fix from $1,600 2025-07-04
Unclassified HIGH 7.5
CVE-2025-6814

The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_now() function in ver…

Mitigation only
Fix from $1,950 2025-07-04
Wp Human Resource Management HIGH 8.8
CVE-2025-5953

The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee(…

Fix: after 2.2.17
Fix from $1,950 2025-07-04
Wp Human Resource Management HIGH 8.1
CVE-2025-5956

The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_…

Fix: after 2.2.17
Fix from $1,950 2025-07-04
Melapress File Monitor MEDIUM 5.4
CVE-2025-3702

Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting Incorrectly Configured Access …

Fix: 2.2.0+
Fix from $1,600 2025-07-03
Meac300 Fnade4 Firmware MEDIUM 6.8
CVE-2025-27461

During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

Mitigation only
Fix from $1,600 2025-07-03
Unclassified MEDIUM 5.3
CVE-2025-53108

HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in the API endpoints responsible…

Patch available
Fix from $1,600 2025-07-02
Unclassified MEDIUM 6.5
CVE-2025-39362

Missing Authorization vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce.This issue affects Mollie Payments for …

Mitigation only
Fix from $1,600 2025-07-02
Unclassified MEDIUM 5.4
CVE-2025-46259

Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control …

Mitigation only
Fix from $1,600 2025-07-01
Pt Project Notebooks CRITICAL 9.8
CVE-2025-5304

The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() func…

Fix: after 1.1.3
Fix from $2,300 2025-06-28