Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Woocommerce Support Ticket System MEDIUM 5.4
CVE-2024-13775

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on …

Fix: 17.9+
Fix from $1,600 2025-02-01
Wp Job Portal MEDIUM 5.3
CVE-2024-13371

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary email…

Fix: 2.2.7+
Fix from $1,600 2025-02-01
Custom Related Posts MEDIUM 5.4
CVE-2024-12825

The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three …

Fix: 1.7.4+
Fix from $1,600 2025-02-01
Magicform MEDIUM 6.3
CVE-2025-0939

The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in…

Fix: after 1.6.2
Fix from $1,600 2025-02-01
Wsdesk HIGH 8.8
CVE-2024-12171

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check …

Fix: 3.2.7+
Fix from $1,950 2025-02-01
Wordpress Contact Forms MEDIUM 5.3
CVE-2024-12184

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the acc…

Fix: 1.9.5+
Fix from $1,600 2025-02-01
Animategl Animations MEDIUM 5.3
CVE-2024-12620

The AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations plugin for WordPress is vulnerable to unauthorized modification of d…

Fix: after 1.4.23
Fix from $1,600 2025-02-01
Woocommerce Customers Manager HIGH 8.8
CVE-2024-13343

The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new…

Fix: 31.4+
Fix from $1,950 2025-02-01
Unclassified MEDIUM 6.5
CVE-2025-22265

Missing Authorization vulnerability in mgplugin EMI Calculator emi-calculator allows Exploiting Incorrectly Configured Access Control Security Levels…

Mitigation only
Fix from $1,600 2025-01-31
Unclassified MEDIUM 5.8
CVE-2025-22720

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorre…

Mitigation only
Fix from $1,600 2025-01-31
Unclassified HIGH 8.1
CVE-2024-13767

The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() functi…

Mitigation only
Fix from $1,950 2025-01-31
Media Manager CRITICAL 9.8
CVE-2024-12822

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a …

Fix: after 3.11.0
Fix from $2,300 2025-01-30
Media Manager MEDIUM 6.5
CVE-2024-12821

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a …

Fix: after 3.12.0
Fix from $1,600 2025-01-30
Royal Core HIGH 8.8
CVE-2024-12129

The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capabil…

Fix: after 2.9.2
Fix from $1,950 2025-01-30
Safe Ai Malware Protection For Wp HIGH 7.5
CVE-2024-12269

The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the expo…

Fix: after 1.0.17
Fix from $1,950 2025-01-30
Hubspot For Woocommerce HIGH 8.8
CVE-2024-10591

The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for WordPress is vulnerable to unauth…

Fix: 1.6.0+
Fix from $1,950 2025-01-30
Account HIGH 8.2
CVE-2025-21396

Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2025-01-29
Android HIGH 8.4
CVE-2024-40677

In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission …

Mitigation only
Fix from $1,950 2025-01-28
Safari MEDIUM 6.5
CVE-2025-24143

The issue was addressed with improved access restrictions to the file system. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Seq…

Fix: 2.3 / 15.3+
Fix from $1,600 2025-01-27
macOS MEDIUM 5.5
CVE-2025-24108

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected…

Fix: 15.3+
Fix from $1,600 2025-01-27
macOS MEDIUM 5.5
CVE-2025-24096

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. A malicious app may be able to access arbitrar…

Fix: 15.3+
Fix from $1,600 2025-01-27
Safari CRITICAL 9.1
CVE-2024-54542

An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.…

Fix: 11.2 / 15.2+
Fix from $2,300 2025-01-27
Unclassified MEDIUM 5.3
CVE-2025-24747

Missing Authorization vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through <= 3.4.0.

Mitigation only
Fix from $1,600 2025-01-27
Unclassified HIGH 8.8
CVE-2025-24734

Missing Authorization vulnerability in CodeSolz Better Find and Replace real-time-auto-find-and-replace allows Privilege Escalation.This issue affect…

Mitigation only
Fix from $1,950 2025-01-27
Unclassified MEDIUM 5.3
CVE-2025-24662

Missing Authorization vulnerability in LearnDash LearnDash LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

No fix yet
Fix from $1,600 2025-01-27
Unclassified MEDIUM 5.3
CVE-2025-24600

Missing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through <= 11.4.5.

No fix yet
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.4
CVE-2025-24606

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access C…

Mitigation only
Fix from $1,600 2025-01-27
Unclassified MEDIUM 5.4
CVE-2025-23849

Missing Authorization vulnerability in bpiwowar PAPERCITE papercite allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Mitigation only
Fix from $1,600 2025-01-27
Unclassified HIGH 7.1
CVE-2025-23982

Missing Authorization vulnerability in Gopi krishnan Fare Calculator fare-calculator allows Stored XSS.This issue affects Fare Calculator: from n/a t…

Mitigation only
Fix from $1,950 2025-01-27
Unclassified MEDIUM 5.3
CVE-2025-24590

Missing Authorization vulnerability in picu picu picu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects picu…

Mitigation only
Fix from $1,600 2025-01-27