Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.0
CVE-2025-32684

Missing Authorization vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Exploiting Incorrectly Configured Access Control S…

Mitigation only
Fix from $1,600 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32624

Missing Authorization vulnerability in czater Czater.pl – live chat i telefon czater allows Cross Site Request Forgery.This issue affects Czater.pl –…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified MEDIUM 5.3
CVE-2025-31042

Missing Authorization vulnerability in rtakao Sandwich Adsense firsth3tagadsense allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2025-04-09
Unclassified HIGH 7.5
CVE-2025-31377

Missing Authorization vulnerability in Asaquzzaman mishu Woo Product Feed For Marketing Channels woocommerce-to-google-merchant-center allows Exploit…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified MEDIUM 5.3
CVE-2025-31012

Missing Authorization vulnerability in Phil Age Gate age-gate allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Age …

Mitigation only
Fix from $1,600 2025-04-09
Melapress Login Security HIGH 8.2
CVE-2025-2876

The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing c…

Fix: 2.1.1+
Fix from $1,950 2025-04-08
Unclassified MEDIUM 5.3
CVE-2025-2568

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due…

Mitigation only
Fix from $1,600 2025-04-08
Motors Car Dealer\, Classifieds \& Listing HIGH 8.8
CVE-2025-2807

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capabi…

Fix: 1.4.65+
Fix from $1,950 2025-04-08
Unclassified MEDIUM 5.3
CVE-2025-26657

SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could expose sensitive information ca…

No fix yet
Fix from $1,600 2025-04-08
Unclassified HIGH 7.7
CVE-2025-27428

Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module.…

Mitigation only
Fix from $1,950 2025-04-08
Harmonyos MEDIUM 5.5
CVE-2025-31171

File read permission bypass vulnerability in the kernel file system module Impact: Successful exploitation of this vulnerability may affect service c…

No fix yet
Fix from $1,600 2025-04-07
Multivendorx MEDIUM 6.5
CVE-2025-2789

The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is …

Fix: 4.2.20+
Fix from $1,600 2025-04-05
Zoomsounds HIGH 8.1
CVE-2024-13776

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a…

Fix: after 6.91
Fix from $1,950 2025-04-05
Unclassified HIGH 8.8
CVE-2025-2933

The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due…

Mitigation only
Fix from $1,950 2025-04-05
Unclassified MEDIUM 5.3
CVE-2025-32258

Missing Authorization vulnerability in InfoGiants Simple Website Logo simple-website-logo allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2025-04-04
Unclassified MEDIUM 5.3
CVE-2025-32256

Missing Authorization vulnerability in devsoftbaltic SurveyJS surveyjs allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff…

Mitigation only
Fix from $1,600 2025-04-04
Unclassified MEDIUM 5.3
CVE-2025-32252

Missing Authorization vulnerability in Black and White WP Genealogy – Your Family History Website wpgenealogy allows Exploiting Incorrectly Configure…

Mitigation only
Fix from $1,600 2025-04-04
Unclassified MEDIUM 5.3
CVE-2025-32253

Missing Authorization vulnerability in ComMotion Course Booking System course-booking-system allows Accessing Functionality Not Properly Constrained …

Mitigation only
Fix from $1,600 2025-04-04
Wpbookit MEDIUM 5.3
CVE-2025-32254

Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff…

Fix: after 1.0.3
Fix from $1,600 2025-04-04
Unclassified MEDIUM 5.4
CVE-2025-32246

Missing Authorization vulnerability in Tim Nguyen 1-Click Backup & Restore Database 1-click-backup-restore-database-by-sunbytes allows Exploiting Inc…

Mitigation only
Fix from $1,600 2025-04-04
Unclassified MEDIUM 5.4
CVE-2025-32218

Missing Authorization vulnerability in RealMag777 TableOn posts-table-filterable allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2025-04-04
Unclassified MEDIUM 5.4
CVE-2025-32219

Missing Authorization vulnerability in Syntactics, Inc. eaSYNC easync-booking allows Exploiting Incorrectly Configured Access Control Security Levels…

Mitigation only
Fix from $1,600 2025-04-04
Salon Booking System HIGH 8.8
CVE-2025-32220

Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Contr…

Fix: after 10.11
Fix from $1,950 2025-04-04
Unclassified MEDIUM 5.4
CVE-2025-32224

Missing Authorization vulnerability in Shivam Mani Tripathi Privyr CRM Integration privy-crm-integration allows Exploiting Incorrectly Configured Acc…

No fix yet
Fix from $1,600 2025-04-04
Unclassified MEDIUM 5.3
CVE-2025-32225

Missing Authorization vulnerability in WP Event Manager WP Event Manager wp-event-manager allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2025-04-04
Unclassified MEDIUM 5.4
CVE-2025-32217

Missing Authorization vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows Exploiting Incorrectly…

Mitigation only
Fix from $1,600 2025-04-04
Unclassified MEDIUM 5.4
CVE-2025-32178

Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Exploiting Incorrectly Configured Access Control Security Le…

No fix yet
Fix from $1,600 2025-04-04
Unclassified HIGH 8.8
CVE-2025-32147

Missing Authorization vulnerability in coothemes Easy WP Optimizer easy-wp-optimizer allows Exploiting Incorrectly Configured Access Control Security…

Mitigation only
Fix from $1,950 2025-04-04
Unclassified MEDIUM 6.5
CVE-2025-31381

Missing Authorization vulnerability in shiptrack Booking Calendar and Notification booking-calendar-and-notification allows Exploiting Incorrectly Co…

Mitigation only
Fix from $1,600 2025-04-04
Unclassified MEDIUM 6.5
CVE-2025-22285

Missing Authorization vulnerability in enituretechnology Pallet Packaging for WooCommerce pallet-packaging-for-woocommerce allows Exploiting Incorrec…

Mitigation only
Fix from $1,600 2025-04-04