Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Superio HIGH 8.8
CVE-2024-12296

The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing cap…

Fix: after 2.3
Fix from $1,950 2025-02-12
Wp Table Manager MEDIUM 6.5
CVE-2024-13374

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in…

Fix: 4.1.4+
Fix from $1,600 2025-02-12
Click Mag HIGH 8.1
CVE-2024-13656

The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a de…

Fix: 3.7.0+
Fix from $1,950 2025-02-12
Puzzles MEDIUM 5.4
CVE-2024-13769

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing…

Fix: 4.2.5+
Fix from $1,600 2025-02-12
Convertplus HIGH 8.1
CVE-2024-13800

The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capabil…

Fix: 3.5.31+
Fix from $1,950 2025-02-12
Zoxpress HIGH 8.8
CVE-2024-13653

The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege …

Fix: 2.12.1+
Fix from $1,950 2025-02-12
Zoxpress HIGH 8.1
CVE-2024-13654

The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial o…

Fix: 2.12.1+
Fix from $1,950 2025-02-12
Adirectory MEDIUM 5.4
CVE-2024-13541

The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check…

Fix: 2.3.5+
Fix from $1,600 2025-02-12
Wp Extended MEDIUM 5.3
CVE-2024-13554

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Fix: 3.0.14+
Fix from $1,600 2025-02-12
Octopus Server MEDIUM 5.4
CVE-2025-0526

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked va…

Fix: 2024.3.13097 / 2024.4.7091+
Fix from $1,600 2025-02-11
Unclassified HIGH 8.8
CVE-2024-13643

The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modification. This vulnerability …

Mitigation only
Fix from $1,950 2025-02-11
Unclassified MEDIUM 5.4
CVE-2025-25241

Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attac…

Mitigation only
Fix from $1,600 2025-02-11
Unclassified MEDIUM 5.3
CVE-2025-23187

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-…

Mitigation only
Fix from $1,600 2025-02-11
Bookpress CRITICAL 9.8
CVE-2025-25167

Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Contro…

Fix: after 1.2.7
Fix from $2,300 2025-02-07
Unclassified MEDIUM 5.4
CVE-2025-25110

Missing Authorization vulnerability in Metagauss Event Kikfyre kikfyre-events-calendar-tickets allows Exploiting Incorrectly Configured Access Contro…

Mitigation only
Fix from $1,600 2025-02-07
Identity Services Engine HIGH 7.2
CVE-2025-20125EPSS 17%

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information…

Fix: 3.1+
Fix from $1,950 2025-02-05
GitLab MEDIUM 6.5
CVE-2024-3976

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and sta…

Fix: 16.9.7 / 16.10.5+
Fix from $1,600 2025-02-05
GitLab MEDIUM 5.3
CVE-2024-1539

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starti…

Fix: 16.9.7 / 16.10.5+
Fix from $1,600 2025-02-05
Unclassified MEDIUM 6.5
CVE-2025-22730

Missing Authorization vulnerability in ksher thailand Ksher ksher-payment allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

No fix yet
Fix from $1,600 2025-02-04
Unclassified MEDIUM 5.4
CVE-2025-22696

Missing Authorization vulnerability in WPDeveloper Document Block – Upload & Embed Docs document.This issue affects Document Block – Upload & Embed D…

Mitigation only
Fix from $1,600 2025-02-04
Unclassified MEDIUM 6.5
CVE-2024-13529

The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capabil…

Mitigation only
Fix from $1,600 2025-02-04
Ds 2105 Pro Firmware HIGH 8.8
CVE-2023-52163 KEVEPSS 97%

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer …

Mitigation only
Fix from $1,950 2025-02-03
Eventer MEDIUM 5.3
CVE-2024-11133

The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' …

Fix: after 3.9.9
Fix from $1,600 2025-02-03
Eventer MEDIUM 6.5
CVE-2024-11134

The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' …

Fix: 3.9.9.1+
Fix from $1,600 2025-02-03
Unclassified MEDIUM 6.5
CVE-2025-24697

Missing Authorization vulnerability in Realwebcare Image Gallery – Responsive Photo Gallery awesome-responsive-photo-gallery allows Exploiting Incorr…

Mitigation only
Fix from $1,600 2025-02-03
Unclassified MEDIUM 6.5
CVE-2025-24642

Missing Authorization vulnerability in theme funda Setup Default Featured Image setup-default-feature-image allows Exploiting Incorrectly Configured …

Mitigation only
Fix from $1,600 2025-02-03
Unclassified MEDIUM 6.5
CVE-2025-24643

Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,600 2025-02-03
Unclassified MEDIUM 6.5
CVE-2025-23527

Missing Authorization vulnerability in hemnathmouli WC Wallet wc-wallet allows Accessing Functionality Not Properly Constrained by ACLs.This issue af…

Mitigation only
Fix from $1,600 2025-02-03
Unclassified MEDIUM 5.3
CVE-2025-22686

Missing Authorization vulnerability in WesternDeal CF7 Google Sheets Connector cf7-google-sheets-connector allows Exploiting Incorrectly Configured A…

Mitigation only
Fix from $1,600 2025-02-03
Shortcodes And Extra Features For Phlox Theme CRITICAL 9.8
CVE-2024-50500

Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured A…

Fix: 2.17.3+
Fix from $2,300 2025-02-03