Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.7
CVE-2025-25244

SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with d…

Mitigation only
Fix from $1,600 2025-03-11
Wp Recall MEDIUM 6.3
CVE-2025-1325

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capabilit…

Fix: 16.26.12+
Fix from $1,600 2025-03-08
Aiomatic MEDIUM 5.4
CVE-2024-13816

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized a…

Fix: 2.3.7+
Fix from $1,600 2025-03-08
Post Lockdown MEDIUM 6.5
CVE-2025-1504

The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2 via the 'pl_autocomplete' AJ…

Fix: after 4.0.2
Fix from $1,600 2025-03-08
School Management System MEDIUM 5.3
CVE-2024-12610

The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '…

Fix: after 93.0.0
Fix from $1,600 2025-03-07
School Management System MEDIUM 5.3
CVE-2024-12611

The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all vers…

Fix: after 93.0.0
Fix from $1,600 2025-03-07
Golo CRITICAL 9.8
CVE-2024-12876

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an…

Fix: 1.6.11+
Fix from $2,300 2025-03-07
Unclassified HIGH 8.8
CVE-2025-1309

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data that …

Mitigation only
Fix from $1,950 2025-03-07
Unclassified HIGH 8.1
CVE-2024-13655

The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of se…

Mitigation only
Fix from $1,950 2025-03-07
Student Manage MEDIUM 6.5
CVE-2025-2042

A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulatio…

Mitigation only
Fix from $1,600 2025-03-06
Unclassified MEDIUM 5.3
CVE-2024-13423

The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_ac…

Mitigation only
Fix from $1,600 2025-03-05
Unclassified MEDIUM 6.5
CVE-2025-0954

The WP Online Contract plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the json_import() and json_expo…

Mitigation only
Fix from $1,600 2025-03-05
Unclassified MEDIUM 6.5
CVE-2024-13780

The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val…

Mitigation only
Fix from $1,600 2025-03-05
Unclassified HIGH 8.8
CVE-2024-13232

The WordPress Awesome Import & Export Plugin - Import & Export WordPress Data plugin for WordPress is vulnerable arbitrary SQL Execution and privileg…

Mitigation only
Fix from $1,950 2025-03-05
Unclassified MEDIUM 5.3
CVE-2024-8682

The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, an…

Mitigation only
Fix from $1,600 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27666

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Authorization Checks OVE-202305…

Fix: 20.0.1923 / 22.0.843+
Fix from $2,300 2025-03-05
Newscrunch CRITICAL 9.8
CVE-2025-1307

The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_p…

Fix: 1.8.4.1+
Fix from $2,300 2025-03-04
Arolax HIGH 8.8
CVE-2025-1639

The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability c…

Fix: 1.7+
Fix from $1,950 2025-03-04
Unclassified CRITICAL 9.8
CVE-2025-27270

Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection allows Privilege Escalation.This…

Mitigation only
Fix from $2,300 2025-03-03
Unclassified MEDIUM 6.5
CVE-2025-23763

Missing Authorization vulnerability in Alex Volkov WAH Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affe…

Mitigation only
Fix from $1,600 2025-03-03
Unclassified MEDIUM 6.5
CVE-2025-23613

Missing Authorization vulnerability in mediabeta WP Journal wpjournal allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Mitigation only
Fix from $1,600 2025-03-03
Unclassified MEDIUM 6.5
CVE-2025-23615

Missing Authorization vulnerability in gtekelis Interactive Page Hierarchy interactive-page-hierarchy allows Exploiting Incorrectly Configured Access…

Mitigation only
Fix from $1,600 2025-03-03
Unclassified MEDIUM 6.5
CVE-2025-23515

Missing Authorization vulnerability in tsecher ts-tree ts-tree allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

No fix yet
Fix from $1,600 2025-03-03
Unclassified MEDIUM 6.3
CVE-2025-23440

Missing Authorization vulnerability in radicaldesigns radSLIDE radslide allows Exploiting Incorrectly Configured Access Control Security Levels.This …

Mitigation only
Fix from $1,600 2025-03-03
Seo Plugin By Squirrly Seo HIGH 8.8
CVE-2025-24654

Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a t…

Fix: 12.4.08+
Fix from $1,950 2025-03-03
Academia Student Information System CRITICAL 9.1
CVE-2025-27583

Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Information System…

Mitigation only
Fix from $2,300 2025-03-03
Academia Student Information System MEDIUM 6.5
CVE-2025-25953

Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. Th…

Mitigation only
Fix from $1,600 2025-03-03
Zz MEDIUM 6.5
CVE-2025-1813

A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manip…

Fix: after 2024-8
Fix from $1,600 2025-03-02
Unclassified MEDIUM 5.3
CVE-2025-1404

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability …

Mitigation only
Fix from $1,600 2025-03-01
Unclassified HIGH 8.8
CVE-2024-12544

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to ar…

Mitigation only
Fix from $1,950 2025-03-01