Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-27013

Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Incorrectly Configured Access Con…

Mitigation only
Fix from $1,600 2025-02-18
Unclassified HIGH 7.5
CVE-2025-22657

Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security…

Mitigation only
Fix from $1,950 2025-02-18
Scratch \& Win MEDIUM 5.3
CVE-2024-13316

The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable …

Fix: 2.9.0+
Fix from $1,600 2025-02-18
Affiliate Links CRITICAL 9.8
CVE-2024-13556

The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all version…

Fix: 3.1.0+
Fix from $2,300 2025-02-18
Get Bookings Wp HIGH 8.8
CVE-2024-13677

The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege escalation via account takeove…

Fix: after 1.1.27
Fix from $1,950 2025-02-18
Analytify Google Analytics Dashboard HIGH 8.8
CVE-2025-26773

Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Fix: 5.5.1+
Fix from $1,950 2025-02-17
Unclassified MEDIUM 5.4
CVE-2025-26765

Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Exploiting Inco…

Mitigation only
Fix from $1,600 2025-02-16
Ltl Freight Quotes CRITICAL 9.8
CVE-2025-22289

Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Unishippers Edition ltl-freight-quotes-unishippers-edition allows Explo…

Fix: 2.5.9+
Fix from $2,300 2025-02-16
Unclassified MEDIUM 5.3
CVE-2025-22291

Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition ltl-freight-quotes-worldwide-express-edition …

Mitigation only
Fix from $1,600 2025-02-16
Wp Project Manager MEDIUM 6.5
CVE-2024-13752

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unau…

Fix: 2.6.18+
Fix from $1,600 2025-02-15
Oliver Pos CRITICAL 9.8
CVE-2024-13513

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in…

Fix: 2.4.2.4+
Fix from $2,300 2025-02-15
Unclassified HIGH 7.1
CVE-2025-24692

Missing Authorization vulnerability in M.Code Bulk Menu Edit bulk-menu-edit allows Exploiting Incorrectly Configured Access Control Security Levels.T…

Mitigation only
Fix from $1,950 2025-02-14
Ideapush CRITICAL 9.8
CVE-2025-24607

Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configured Access Control Security L…

Fix: 8.73+
Fix from $2,300 2025-02-14
Unclassified MEDIUM 6.5
CVE-2025-23766

Missing Authorization vulnerability in ashamil OPSI Israel Domestic Shipments woo-ups-pickup allows Exploiting Incorrectly Configured Access Control …

Mitigation only
Fix from $1,600 2025-02-14
Unclassified MEDIUM 6.5
CVE-2025-23771

Missing Authorization vulnerability in Murali Push Notification for Post and BuddyPress push-notification-for-post-and-buddypress allows Exploiting I…

Mitigation only
Fix from $1,600 2025-02-14
Unclassified MEDIUM 6.5
CVE-2025-23534

Missing Authorization vulnerability in Mark Winiarski WPLingo wplingo allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Mitigation only
Fix from $1,600 2025-02-14
Unclassified HIGH 7.2
CVE-2024-52500

Missing Authorization vulnerability in monetagwp Monetag Official Plugin monetag-official allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,950 2025-02-14
Unclassified MEDIUM 6.3
CVE-2025-22698

Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrectly Configured Access Control …

Mitigation only
Fix from $1,600 2025-02-14
Unclassified MEDIUM 6.3
CVE-2025-22702

Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

No fix yet
Fix from $1,600 2025-02-14
Maxair HIGH 8.8
CVE-2025-1214

A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of th…

No fix yet
Fix from $1,950 2025-02-12
Maxtime HIGH 8.8
CVE-2025-26378

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime HIGH 8.8
CVE-2025-26371

A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime HIGH 8.1
CVE-2025-26372

A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime MEDIUM 6.5
CVE-2025-26373

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an aut…

Fix: after 2.11.0
Fix from $1,600 2025-02-12
Maxtime HIGH 8.8
CVE-2025-26375

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime MEDIUM 6.5
CVE-2025-26376

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-…

Fix: after 2.11.0
Fix from $1,600 2025-02-12
Maxtime HIGH 8.1
CVE-2025-26377

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime HIGH 8.1
CVE-2025-26368

A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime HIGH 8.8
CVE-2025-26369

A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime HIGH 7.1
CVE-2025-26370

A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated…

Fix: after 2.11.0
Fix from $1,950 2025-02-12