Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Xwiki CRITICAL 9.0
CVE-2025-32973

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to …

Fix: 15.10.12 / 16.4.3+
Fix from $2,300 2025-04-30
Unclassified MEDIUM 5.4
CVE-2025-3953

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to…

Mitigation only
Fix from $1,600 2025-04-30
Yeswiki CRITICAL 9.8
CVE-2025-46348

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authen…

Fix: 4.5.4+
Fix from $2,300 2025-04-29
Online Traveling System MEDIUM 5.3
CVE-2025-4064

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file …

Mitigation only
Fix from $1,600 2025-04-29
Unclassified MEDIUM 5.3
CVE-2025-39367

Missing Authorization vulnerability in SeventhQueen Kleo kleo.This issue affects Kleo: from n/a through < 5.4.4.

No fix yet
Fix from $1,600 2025-04-28
Internet Doctor Workstation System MEDIUM 5.3
CVE-2025-3981

A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. T…

No fix yet
Fix from $1,600 2025-04-27
Lecms MEDIUM 6.5
CVE-2025-3979

A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-aja…

No fix yet
Fix from $1,600 2025-04-27
Internet Doctor Workstation System MEDIUM 5.3
CVE-2025-3980

A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This vulnerability…

No fix yet
Fix from $1,600 2025-04-27
Books Management System CRITICAL 9.8
CVE-2025-3963

A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processin…

No fix yet
Fix from $2,300 2025-04-27
Books Management System CRITICAL 9.8
CVE-2025-3960

A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionali…

No fix yet
Fix from $2,300 2025-04-27
Unclassified HIGH 8.8
CVE-2025-3906

The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on…

Mitigation only
Fix from $1,950 2025-04-26
Dify HIGH 7.6
CVE-2025-43862

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even thou…

Fix: 0.6.12+
Fix from $1,950 2025-04-25
Moodle MEDIUM 5.3
CVE-2025-32045

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to…

Fix: 4.1.17 / 4.3.11+
Fix from $1,600 2025-04-25
Unclassified MEDIUM 5.3
CVE-2025-3912

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Mitigation only
Fix from $1,600 2025-04-25
Unclassified HIGH 8.8
CVE-2025-1279

The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing…

Mitigation only
Fix from $1,950 2025-04-25
Unclassified MEDIUM 5.4
CVE-2025-46535

Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Secu…

No fix yet
Fix from $1,600 2025-04-25
Unclassified MEDIUM 5.3
CVE-2025-46485

Missing Authorization vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Accessing Functionality Not Properly Cons…

Mitigation only
Fix from $1,600 2025-04-24
Unclassified MEDIUM 5.3
CVE-2025-46489

Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce wc-bulk-assign-linked-products allows Accessing Func…

Mitigation only
Fix from $1,600 2025-04-24
Unclassified MEDIUM 5.3
CVE-2025-39390

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Function…

Mitigation only
Fix from $1,600 2025-04-24
Unclassified HIGH 7.5
CVE-2021-47662

Due to missing authorization an unauthenticated remote attacker can cause a DoS attack by connecting via HTTPS and triggering the shutdown button.

Mitigation only
Fix from $1,950 2025-04-24
Flynax Bridge CRITICAL 9.8
CVE-2025-3604

The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This i…

Fix: after 2.2.0
Fix from $2,300 2025-04-24
Unclassified HIGH 8.8
CVE-2025-3058

The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing cap…

Mitigation only
Fix from $1,950 2025-04-24
Unclassified MEDIUM 5.3
CVE-2024-13307

The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capabili…

Mitigation only
Fix from $1,600 2025-04-24
Diskstation Manager HIGH 7.5
CVE-2025-1021

Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows re…

Fix: 7.1.1-42962-8 / 7.2.1-69057-7+
Fix from $1,950 2025-04-23
Unclassified CRITICAL 9.8
CVE-2025-37087

A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the …

Mitigation only
Fix from $2,300 2025-04-22
Appointment Booking Calendar CRITICAL 9.8
CVE-2025-46247

Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Proper…

Fix: 1.3.93+
Fix from $2,300 2025-04-22
Advanced Linked Variations For Woocommerce CRITICAL 9.8
CVE-2025-46244

Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Exploiting Incorrectly Configured …

Fix: 1.0.4+
Fix from $2,300 2025-04-22
Alt Text Ai HIGH 8.8
CVE-2025-46232

Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Lev…

Fix: 1.9.94+
Fix from $1,950 2025-04-22
Ds Java MEDIUM 6.5
CVE-2025-3843

A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to…

No fix yet
Fix from $1,600 2025-04-21
Flaskblog MEDIUM 6.4
CVE-2025-28103

Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.

Mitigation only
Fix from $1,600 2025-04-21