Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-30887

Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Leve…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.3
CVE-2025-30866

Missing Authorization vulnerability in Giannis Kipouros Terms & Conditions Per Product terms-and-conditions-per-product allows Exploiting Incorrectly…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.3
CVE-2025-30839

Missing Authorization vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Exploiting Incorrectly Co…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.3
CVE-2025-30828

Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.3
CVE-2025-30830

Missing Authorization vulnerability in Hossni Mubarak Cool Author Box hm-cool-author-box-widget allows Exploiting Incorrectly Configured Access Contr…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.3
CVE-2025-30821

Missing Authorization vulnerability in otacke SNORDIAN's H5PxAPIkatchu h5pxapikatchu allows Accessing Functionality Not Properly Constrained by ACLs.…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.4
CVE-2025-30824

Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access Control Security Levels.This i…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.4
CVE-2025-30817

Missing Authorization vulnerability in wpzita Z Companion z-companion allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.4
CVE-2025-30809

Missing Authorization vulnerability in Shahjada Live Forms liveforms allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified MEDIUM 5.3
CVE-2025-30790

Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Accessing Functionality Not Properly Constrained by ACLs.Thi…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified HIGH 8.8
CVE-2025-30772

Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce wpc-smart-upsell-funnel allows Privilege Escalation.This issu…

Mitigation only
Fix from $1,950 2025-03-27
Unclassified MEDIUM 5.4
CVE-2025-30767

Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security L…

Mitigation only
Fix from $1,600 2025-03-27
Wp Compress HIGH 8.8
CVE-2025-2110

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data …

Fix: 6.30.16+
Fix from $1,950 2025-03-26
Unclassified HIGH 8.1
CVE-2024-13801

The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a mi…

Mitigation only
Fix from $1,950 2025-03-26
Unclassified MEDIUM 5.3
CVE-2025-2224

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and mod…

Mitigation only
Fix from $1,600 2025-03-25
Unclassified MEDIUM 5.3
CVE-2025-30591

Missing Authorization vulnerability in tuyennv Music Press Pro music-press-pro allows Exploiting Incorrectly Configured Access Control Security Level…

No fix yet
Fix from $1,600 2025-03-24
Unclassified MEDIUM 5.3
CVE-2025-30592

Missing Authorization vulnerability in WesternDeal Advanced Dewplayer advanced-dewplayer allows Exploiting Incorrectly Configured Access Control Secu…

Mitigation only
Fix from $1,600 2025-03-24
Unclassified MEDIUM 5.3
CVE-2025-30581

Missing Authorization vulnerability in PluginOps Top Bar ultimate-bar allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Mitigation only
Fix from $1,600 2025-03-24
Human Resource Management CRITICAL 9.8
CVE-2025-2589

A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index o…

No fix yet
Fix from $2,300 2025-03-21
Infocad CRITICAL 9.8
CVE-2025-26853

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.

Fix: 3.5.2.0+
Fix from $2,300 2025-03-20
Lunary CRITICAL 9.8
CVE-2024-9095

In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Googl…

Patch available
Fix from $2,300 2025-03-20
Lunary HIGH 7.1
CVE-2024-9096

In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending a PATCH request. The route l…

Patch available
Fix from $1,950 2025-03-20
Lunary HIGH 7.5
CVE-2024-8999

lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnera…

Fix: 1.4.26+
Fix from $1,950 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-9000

In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the …

Patch available
Fix from $1,600 2025-03-20
Onyx HIGH 8.1
CVE-2024-7767

An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system…

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 8.8
CVE-2024-7043

An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not veri…

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 7.1
CVE-2024-2292

Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users.

Mitigation only
Fix from $1,950 2025-03-20
Lunary HIGH 8.1
CVE-2024-10762

In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by sending a DELETE request. Ho…

Fix: 1.5.9+
Fix from $1,950 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-10330

In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch a…

Fix: 1.5.7+
Fix from $1,600 2025-03-20
Librechat MEDIUM 5.4
CVE-2024-10363

In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being …

Patch available
Fix from $1,600 2025-03-20