Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-47563

Missing Authorization vulnerability in villatheme CURCY woocommerce-multi-currency allows Accessing Functionality Not Properly Constrained by ACLs.Th…

Mitigation only
Fix from $1,600 2025-05-16
Unclassified MEDIUM 5.3
CVE-2025-47564

Missing Authorization vulnerability in ashanjay EventON eventon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ev…

Mitigation only
Fix from $1,600 2025-05-16
Unclassified MEDIUM 5.4
CVE-2025-47556

Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Exploiting Incorre…

Mitigation only
Fix from $1,600 2025-05-16
Eventer HIGH 8.8
CVE-2025-39482

Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

Fix: after 3.9.6
Fix from $1,950 2025-05-16
Rankie HIGH 8.8
CVE-2025-39493

Missing Authorization vulnerability in ValvePress Rankie valvepress-rankie allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Fix: 1.8.2+
Fix from $1,950 2025-05-16
Unclassified MEDIUM 5.3
CVE-2025-32296

Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Co…

Mitigation only
Fix from $1,600 2025-05-16
Unclassified MEDIUM 5.4
CVE-2025-31923

Missing Authorization vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Exploiting Incorrectly Configured Access Con…

Mitigation only
Fix from $1,600 2025-05-16
Unclassified MEDIUM 5.3
CVE-2025-31071

Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,600 2025-05-16
Unclassified MEDIUM 5.3
CVE-2025-31630

Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affe…

Mitigation only
Fix from $1,600 2025-05-16
Unclassified MEDIUM 5.3
CVE-2025-31065

Missing Authorization vulnerability in themeton Rozario allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects R…

No fix yet
Fix from $1,600 2025-05-16
Unclassified MEDIUM 5.3
CVE-2025-31066

Missing Authorization vulnerability in themeton Acerola acerola allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

Mitigation only
Fix from $1,600 2025-05-16
Desktop MEDIUM 6.1
CVE-2025-47792

Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed o…

Fix: 3.15.0+
Fix from $1,600 2025-05-16
Wp Erp HIGH 7.5
CVE-2024-12812

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDO…

Fix: 1.13.4+
Fix from $1,950 2025-05-15
Unclassified MEDIUM 5.3
CVE-2024-56006

Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a before 2.0.1.

Mitigation only
Fix from $1,600 2025-05-15
Front End Users CRITICAL 9.8
CVE-2025-47580

Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Securi…

Fix: after 3.2.32
Fix from $2,300 2025-05-15
Unclassified HIGH 8.1
CVE-2024-58101

Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequenc…

Mitigation only
Fix from $1,950 2025-05-14
Miniorange 2fa MEDIUM 6.5
CVE-2025-47709

Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Dr…

Fix: 5.2.0 / 8.x-4.7+
Fix from $1,600 2025-05-14
Itop MEDIUM 5.0
CVE-2025-24021

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set valu…

Fix: 2.7.12 / 3.1.3+
Fix from $1,600 2025-05-14
Unclassified HIGH 8.6
CVE-2025-4430

Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in versions before 20.19 (publishe…

Mitigation only
Fix from $1,950 2025-05-14
Unclassified HIGH 7.7
CVE-2025-43011

Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated…

Mitigation only
Fix from $1,950 2025-05-13
Unclassified MEDIUM 5.3
CVE-2025-43004

Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enable outside users to access cus…

Mitigation only
Fix from $1,600 2025-05-13
Unclassified MEDIUM 6.3
CVE-2025-43007

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privil…

Mitigation only
Fix from $1,600 2025-05-13
Unclassified MEDIUM 5.8
CVE-2025-43008

Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of emplo…

Mitigation only
Fix from $1,600 2025-05-13
Unclassified MEDIUM 6.3
CVE-2025-43009

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privil…

Mitigation only
Fix from $1,600 2025-05-13
Unclassified HIGH 7.9
CVE-2025-43000

Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High…

Mitigation only
Fix from $1,950 2025-05-13
Ipados CRITICAL 9.1
CVE-2025-30448

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macO…

Fix: 2.5 / 13.7.6+
Fix from $2,300 2025-05-12
Unclassified MEDIUM 6.5
CVE-2025-46745

An authenticated user without user-management permissions could view other users account information.

Mitigation only
Fix from $1,600 2025-05-12
Znuny CRITICAL 9.8
CVE-2025-26846

An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.

Fix: after 7.1.3
Fix from $2,300 2025-05-12
Sms Alert Order Notifications HIGH 8.8
CVE-2025-3876

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in…

Fix: 3.8.2+
Fix from $1,950 2025-05-10
Rx1800 Firmware HIGH 8.8
CVE-2025-28202

Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.

No fix yet
Fix from $1,950 2025-05-09