Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.4
CVE-2025-48335

Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Exploiting Incorrectly Configured Access Control Securit…

Mitigation only
Fix from $1,600 2025-06-06
Hr Portal HIGH 7.5
CVE-2025-48784

A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to mod…

Fix: after 7.3.2025.0408
Fix from $1,950 2025-06-06
Traffic Offense Reporting System HIGH 8.8
CVE-2025-5732

A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part. …

No fix yet
Fix from $1,950 2025-06-06
Unclassified CRITICAL 9.8
CVE-2025-5486

The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() func…

Mitigation only
Fix from $2,300 2025-06-06
Unclassified HIGH 7.1
CVE-2025-5018

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_updat…

Mitigation only
Fix from $1,950 2025-06-06
Unclassified MEDIUM 6.4
CVE-2025-1777

The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'ux_cb_page_optio…

Mitigation only
Fix from $1,600 2025-06-06
Uncanny Automator CRITICAL 9.8
CVE-2025-48133

Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Securi…

Fix: 6.5.0+
Fix from $2,300 2025-06-05
Unclassified MEDIUM 5.4
CVE-2025-46258

Missing Authorization vulnerability in BdThemes Element Pack Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

Mitigation only
Fix from $1,600 2025-06-05
Unclassified HIGH 8.8
CVE-2025-5701

The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capa…

Mitigation only
Fix from $1,950 2025-06-05
Wukong Crm HIGH 8.8
CVE-2025-5521

A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functi…

No fix yet
Fix from $1,950 2025-06-03
Dataease HIGH 8.8
CVE-2025-48998

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allow…

Fix: 2.10.6+
Fix from $1,950 2025-06-03
Jehc Bpm CRITICAL 10.0
CVE-2025-45854

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

Fix: after 2.0.1
Fix from $2,300 2025-06-03
Unclassified MEDIUM 6.5
CVE-2025-47585

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Function…

Mitigation only
Fix from $1,600 2025-06-02
Unclassified MEDIUM 6.5
CVE-2025-4597

The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missin…

Mitigation only
Fix from $1,600 2025-05-30
Unclassified HIGH 8.0
CVE-2025-46823

openmrs-module-fhir2 provides the FHIR REST API and related services for OpenMRS, an open medical records system. In versions of the FHIR2 module pri…

Mitigation only
Fix from $1,950 2025-05-29
Unclassified MEDIUM 5.3
CVE-2025-40673

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessin…

Mitigation only
Fix from $1,600 2025-05-28
Unclassified HIGH 8.8
CVE-2025-5117

The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_rol…

Mitigation only
Fix from $1,950 2025-05-27
Unclassified CRITICAL 9.3
CVE-2025-2407

Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vuln…

Mitigation only
Fix from $2,300 2025-05-27
Gim MEDIUM 6.5
CVE-2025-40667

Missing authorization vulnerability in TCMAN's GIM v11. This allows an authenticated attacker to access any functionality of the application even whe…

Mitigation only
Fix from $1,600 2025-05-26
Tmall Demo HIGH 8.8
CVE-2025-5132

A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file tmal…

Fix: after 2025-05-05
Fix from $1,950 2025-05-24
Unclassified MEDIUM 6.5
CVE-2025-48275

Missing Authorization vulnerability in dastan800 Visual Header visual-header allows Exploiting Incorrectly Configured Access Control Security Levels.…

Mitigation only
Fix from $1,600 2025-05-23
Unclassified HIGH 8.8
CVE-2025-47690

Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Privilege Escalation.This i…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified MEDIUM 6.5
CVE-2025-48271

Missing Authorization vulnerability in Leadinfo Leadinfo leadinfo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

No fix yet
Fix from $1,600 2025-05-23
Unclassified MEDIUM 6.5
CVE-2025-47619

Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affects 6Storage Rentals: from n/a…

Mitigation only
Fix from $1,600 2025-05-23
Unclassified HIGH 7.5
CVE-2025-47558

Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Map…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified MEDIUM 6.5
CVE-2025-47529

Missing Authorization vulnerability in UX Design Experts Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin experto-cta-widget a…

Mitigation only
Fix from $1,600 2025-05-23
Unclassified HIGH 7.1
CVE-2025-46488

Missing Authorization vulnerability in dastan800 Visual Builder visual-builder allows Reflected XSS.This issue affects Visual Builder: from n/a throu…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified HIGH 8.2
CVE-2025-39536

Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Control Security Levels. This i…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified MEDIUM 5.3
CVE-2025-2506

When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a datab…

Mitigation only
Fix from $1,600 2025-05-22
Unclassified MEDIUM 5.3
CVE-2025-47942

The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxapp has no built-in protection …

Patch available
Fix from $1,600 2025-05-21