Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Lunary HIGH 7.5
CVE-2024-10272

lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of au…

Fix: 1.4.9+
Fix from $1,950 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-10274

An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequate access control mechanisms…

Fix: 1.5.7+
Fix from $1,600 2025-03-20
Eventin MEDIUM 5.3
CVE-2025-1766

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a…

Fix: 4.0.25+
Fix from $1,600 2025-03-20
Xwiki CRITICAL 9.8
CVE-2025-29926

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki…

Fix: 15.10.15 / 16.4.6+
Fix from $2,300 2025-03-19
Unclassified HIGH 8.8
CVE-2024-12920

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of d…

Mitigation only
Fix from $1,950 2025-03-19
Unclassified HIGH 7.5
CVE-2024-13412

The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in…

Mitigation only
Fix from $1,950 2025-03-19
Unclassified CRITICAL 9.8
CVE-2024-12922

The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability c…

Mitigation only
Fix from $2,300 2025-03-19
Lifterlms MEDIUM 5.3
CVE-2025-2290

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing …

Fix: 8.0.2+
Fix from $1,600 2025-03-19
Unclassified HIGH 7.5
CVE-2025-30107

On IROAD V9 devices, Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. A vulner…

Mitigation only
Fix from $1,950 2025-03-18
Unclassified HIGH 7.3
CVE-2025-2262

The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortco…

Mitigation only
Fix from $1,950 2025-03-18
Unclassified HIGH 8.3
CVE-2025-26969

Missing Authorization vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.

Mitigation only
Fix from $1,950 2025-03-15
Unclassified HIGH 8.6
CVE-2025-26961

Missing Authorization vulnerability in FRESHFACE Fresh Framework fresh-framework allows Accessing Functionality Not Properly Constrained by ACLs.This…

Mitigation only
Fix from $1,950 2025-03-15
Givewp HIGH 7.5
CVE-2025-2025

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c…

Fix: 3.22.1+
Fix from $1,950 2025-03-15
Wp01 MEDIUM 6.5
CVE-2025-2267

The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check …

Fix: after 2.6.2
Fix from $1,600 2025-03-15
Wpschoolpress MEDIUM 5.4
CVE-2025-1668

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the w…

Fix: after 2.2.16
Fix from $1,600 2025-03-15
Wc Affiliate MEDIUM 6.5
CVE-2024-12336

The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil…

Fix: 2.6+
Fix from $1,600 2025-03-15
Ulisting HIGH 8.8
CVE-2025-1657

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection d…

Fix: after 2.1.7
Fix from $1,950 2025-03-15
Jobcareer HIGH 8.1
CVE-2024-12810

The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to …

Fix: after 7.1
Fix from $1,950 2025-03-14
Dashboard For Google Analytics MEDIUM 5.3
CVE-2025-1507

The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec…

Fix: 3.2.2+
Fix from $1,600 2025-03-14
Soundrise HIGH 8.8
CVE-2025-2103

The SoundRise Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing ca…

Fix: 1.7.1+
Fix from $1,950 2025-03-14
Zegen HIGH 8.8
CVE-2025-2289

The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX endpoin…

Fix: after 1.1.9
Fix from $1,950 2025-03-14
Unclassified HIGH 8.1
CVE-2025-0952

The Eco Nature - Environment & Ecology WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a deni…

Mitigation only
Fix from $1,950 2025-03-14
Unclassified MEDIUM 5.3
CVE-2025-0955

The VidoRev Extensions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'vidorev_import_single_vide…

Mitigation only
Fix from $1,600 2025-03-14
Unclassified MEDIUM 5.3
CVE-2025-1285

The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api…

Mitigation only
Fix from $1,600 2025-03-14
Dataease MEDIUM 6.5
CVE-2025-24974

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize a…

Fix: 2.10.6+
Fix from $1,600 2025-03-13
Dataease MEDIUM 6.5
CVE-2025-27103

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allo…

Fix: 2.10.6+
Fix from $1,600 2025-03-13
Wp Crowdfunding MEDIUM 5.3
CVE-2025-1508

The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action i…

Fix: after 2.1.13
Fix from $1,600 2025-03-12
Unclassified MEDIUM 5.3
CVE-2025-28920

Missing Authorization vulnerability in Jogesh Responsive Google Map responsive-google-map allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2025-03-11
Block Spam By Math Reloaded CRITICAL 9.8
CVE-2025-28872

Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Accessing Functionality Not Properly C…

Fix: after 2.2.4
Fix from $2,300 2025-03-11
Unclassified HIGH 8.8
CVE-2025-26661

Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulti…

Mitigation only
Fix from $1,950 2025-03-11