Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
macOS CRITICAL 9.8
CVE-2025-24181

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
Open Social CRITICAL 9.1
CVE-2025-31685

Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12…

Fix: 12.3.11 / 12.4.10+
Fix from $2,300 2025-03-31
Open Social HIGH 8.1
CVE-2025-31686

Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12…

Fix: 12.3.11 / 12.4.10+
Fix from $1,950 2025-03-31
Oauth2 Server CRITICAL 9.8
CVE-2025-31691

Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.

Fix: 2.1.0+
Fix from $2,300 2025-03-31
Artificial Intelligence HIGH 8.2
CVE-2025-31678

Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): …

Fix: 1.0.3+
Fix from $1,950 2025-03-31
Authenticator Login CRITICAL 9.8
CVE-2025-31681

Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before …

Fix: 2.0.6+
Fix from $2,300 2025-03-31
Unclassified MEDIUM 5.3
CVE-2025-31618

Missing Authorization vulnerability in Jaap Jansma Connector to CiviCRM with CiviMcRestFace connector-civicrm-mcrestface allows Exploiting Incorrectl…

Mitigation only
Fix from $1,600 2025-03-31
Unclassified MEDIUM 5.4
CVE-2025-31603

Missing Authorization vulnerability in moshensky CF7 Spreadsheets cf7-spreadsheets allows Exploiting Incorrectly Configured Access Control Security L…

Mitigation only
Fix from $1,600 2025-03-31
Unclassified MEDIUM 5.4
CVE-2025-31584

Missing Authorization vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Exploiting Incorrectly Configured Ac…

Mitigation only
Fix from $1,600 2025-03-31
Unclassified MEDIUM 5.4
CVE-2025-31555

Missing Authorization vulnerability in ContentMX ContentMX Content Publisher contentmx-content-publisher allows Exploiting Incorrectly Configured Acc…

Mitigation only
Fix from $1,600 2025-03-31
Unclassified MEDIUM 5.4
CVE-2025-31545

Missing Authorization vulnerability in WP Messiah Safe Ai Malware Protection for WP safe-ai-malware-protection-for-wp allows Exploiting Incorrectly C…

Mitigation only
Fix from $1,600 2025-03-31
Unclassified MEDIUM 5.3
CVE-2025-31533

Missing Authorization vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms gf-salesmate-add-on allows Accessing Functionality Not Properl…

Mitigation only
Fix from $1,600 2025-03-31
Unclassified MEDIUM 6.5
CVE-2025-31539

Missing Authorization vulnerability in Blocksera Cryptocurrency Widgets Pack cryptocurrency-widgets-pack allows Exploiting Incorrectly Configured Acc…

Mitigation only
Fix from $1,600 2025-03-31
Unclassified MEDIUM 5.3
CVE-2025-31386

Missing Authorization vulnerability in simplepress Simple:Press simplepress allows Exploiting Incorrectly Configured Access Control Security Levels.T…

Mitigation only
Fix from $1,600 2025-03-31
Unclassified HIGH 7.5
CVE-2025-30855

Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Exploiting Incorrectly Configured Access Control S…

Mitigation only
Fix from $1,950 2025-03-31
Unclassified CRITICAL 9.8
CVE-2025-2266

The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat…

Mitigation only
Fix from $2,300 2025-03-29
Unclassified MEDIUM 5.3
CVE-2025-31469

Missing Authorization vulnerability in webrangers Clear Sucuri Cache clear-sucuri-cache allows Exploiting Incorrectly Configured Access Control Secur…

Mitigation only
Fix from $1,600 2025-03-28
Unclassified HIGH 8.8
CVE-2025-2815

The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing ca…

Mitigation only
Fix from $1,950 2025-03-28
Unclassified HIGH 8.2
CVE-2025-26733

Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

Mitigation only
Fix from $1,950 2025-03-27
Unclassified HIGH 7.6
CVE-2025-26956

Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

Mitigation only
Fix from $1,950 2025-03-27
Unclassified MEDIUM 5.3
CVE-2025-22739

Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This i…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.3
CVE-2025-22740

Missing Authorization vulnerability in Automattic Sensei LMS sensei-lms allows Exploiting Incorrectly Configured Access Control Security Levels.This …

Mitigation only
Fix from $1,600 2025-03-27
Mealie MEDIUM 5.4
CVE-2024-55072

A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profi…

No fix yet
Fix from $1,600 2025-03-27
Mealie HIGH 7.6
CVE-2024-55073

A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profi…

No fix yet
Fix from $1,950 2025-03-27
Unclassified MEDIUM 5.3
CVE-2025-22629

Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 6.5
CVE-2025-22670

Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Exploiting Incorrectly Configured Access Cont…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 6.5
CVE-2025-22668

Missing Authorization vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Exploiting Incorrectly Configured Access Contro…

No fix yet
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.4
CVE-2025-22770

Missing Authorization vulnerability in EnvoThemes Envo Multipurpose allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

No fix yet
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.4
CVE-2025-30896

Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects W…

Mitigation only
Fix from $1,600 2025-03-27
Big Store MEDIUM 5.4
CVE-2025-30881

Missing Authorization vulnerability in themehunk Big Store big-store allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Fix: 2.0.9+
Fix from $1,600 2025-03-27