Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2025-49234

Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Ac…

Mitigation only
Fix from $1,600 2025-06-17
Jfinal Cms HIGH 8.8
CVE-2025-6105

A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.ja…

No fix yet
Fix from $1,950 2025-06-16
Bookable Calendar MEDIUM 6.5
CVE-2025-48916

Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.…

Fix: 2.2.13+
Fix from $1,600 2025-06-13
Unclassified MEDIUM 5.3
CVE-2025-5815

The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_b…

Mitigation only
Fix from $1,600 2025-06-13
Wp Travel Engine HIGH 7.5
CVE-2025-5282

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing …

Fix: 6.5.2+
Fix from $1,950 2025-06-13
Unclassified CRITICAL 9.8
CVE-2025-5288

The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a mi…

Mitigation only
Fix from $2,300 2025-06-13
Media Server HIGH 8.6
CVE-2025-49181

Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could als…

Mitigation only
Fix from $1,950 2025-06-12
Quick Node Block MEDIUM 5.3
CVE-2025-48444

Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.

Mitigation only
Fix from $1,600 2025-06-11
Quick Node Block MEDIUM 5.3
CVE-2025-48013

Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.

Mitigation only
Fix from $1,600 2025-06-11
Unclassified HIGH 8.3
CVE-2025-29756

SunGrow's back end users system iSolarCloud https://isolarcloud.com  uses an MQTT service to transport data from the user's connected devices to the…

Mitigation only
Fix from $1,950 2025-06-11
Unclassified MEDIUM 5.6
CVE-2025-1055

A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL reque…

Mitigation only
Fix from $1,600 2025-06-11
Geoserver MEDIUM 5.3
CVE-2025-27505

GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the default REST API security and ac…

Fix: 2.25.6 / 2.26.3+
Fix from $1,600 2025-06-10
Unclassified MEDIUM 5.3
CVE-2025-49509

Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Exploiting Incorrectly Configured Access…

Mitigation only
Fix from $1,600 2025-06-10
Unclassified CRITICAL 9.6
CVE-2025-42989

RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successfu…

Mitigation only
Fix from $2,300 2025-06-10
Unclassified MEDIUM 6.7
CVE-2025-42993

Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Confi…

Mitigation only
Fix from $1,600 2025-06-10
Unclassified HIGH 8.8
CVE-2025-42982

SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system creden…

Mitigation only
Fix from $1,950 2025-06-10
Unclassified HIGH 8.5
CVE-2025-42983

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss …

Mitigation only
Fix from $1,950 2025-06-10
Unclassified MEDIUM 5.4
CVE-2025-42984

SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker coul…

Mitigation only
Fix from $1,600 2025-06-10
Ac9 Firmware HIGH 7.1
CVE-2025-5900

A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cro…

No fix yet
Fix from $1,950 2025-06-09
Webstack Guns MEDIUM 6.5
CVE-2025-5888

A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionalit…

No fix yet
Fix from $1,600 2025-06-09
Unclassified HIGH 8.1
CVE-2025-49651

Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in…

Mitigation only
Fix from $1,950 2025-06-09
Unclassified HIGH 7.5
CVE-2025-49265

Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Co…

Mitigation only
Fix from $1,950 2025-06-09
Unclassified MEDIUM 6.5
CVE-2025-48147

Missing Authorization vulnerability in Crypto Cloud CryptoCloud - Crypto Payment Gateway cryptocloud-crypto-payment-gateway allows Exploiting Incorre…

Mitigation only
Fix from $1,600 2025-06-09
Unclassified MEDIUM 6.5
CVE-2025-48139

Missing Authorization vulnerability in relentlo StyleAI relentlosoftware allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…

Mitigation only
Fix from $1,600 2025-06-09
Unclassified HIGH 7.1
CVE-2025-47527

Missing Authorization vulnerability in Icegram Icegram Collect icegram-rainmaker allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,950 2025-06-09
Unclassified HIGH 7.1
CVE-2025-47463

Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Co…

Mitigation only
Fix from $1,950 2025-06-09
Unclassified HIGH 7.6
CVE-2025-32308

Missing Authorization vulnerability in looks_awesome Team Builder a-team-showcase allows Exploiting Incorrectly Configured Access Control Security Le…

Mitigation only
Fix from $1,950 2025-06-09
Unclassified HIGH 8.8
CVE-2025-5894

Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attackers with regular privileges …

Mitigation only
Fix from $1,950 2025-06-09
Unclassified HIGH 8.8
CVE-2025-47601

Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a…

Mitigation only
Fix from $1,950 2025-06-07
Unclassified MEDIUM 5.3
CVE-2025-5814

The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on…

Mitigation only
Fix from $1,600 2025-06-07