Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2025-23656

Missing Authorization vulnerability in Saul Morales Pacheco Donate visa donate-visa allows Stored XSS.This issue affects Donate visa: from n/a throug…

Mitigation only
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.5
CVE-2025-23529

Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue …

Mitigation only
Fix from $1,600 2025-01-27
Zox News HIGH 8.8
CVE-2024-11936

The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability…

Fix: 3.17.0+
Fix from $1,950 2025-01-26
Unclassified HIGH 7.2
CVE-2024-10574

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability c…

Mitigation only
Fix from $1,950 2025-01-26
Youzify MEDIUM 6.5
CVE-2024-13370

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized…

Fix: after 1.3.3
Fix from $1,600 2025-01-25
Unclassified MEDIUM 5.4
CVE-2025-24750

Missing Authorization vulnerability in Syed Balkhi ExactMetrics google-analytics-dashboard-for-wp allows Exploiting Incorrectly Configured Access Con…

Mitigation only
Fix from $1,600 2025-01-24
Gutenberg Blocks With Ai HIGH 8.8
CVE-2025-24753

Missing Authorization vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Exploiting Incorrectly Configured Access Co…

Fix: 3.3.2+
Fix from $1,950 2025-01-24
Unclassified MEDIUM 5.3
CVE-2025-24705

Missing Authorization vulnerability in Arshid WooCommerce Quick View woo-quick-view allows Exploiting Incorrectly Configured Access Control Security …

Mitigation only
Fix from $1,600 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24652

Missing Authorization vulnerability in revmakx WP Duplicate local-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This i…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified MEDIUM 5.3
CVE-2025-24633

Missing Authorization vulnerability in silverplugins217 Build Private Store For Woocommerce build-private-store-for-woocommerce allows Exploiting Inc…

Mitigation only
Fix from $1,600 2025-01-24
Elementinvader Addons For Elementor HIGH 8.8
CVE-2025-24618

Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Inco…

Fix: 1.3.2+
Fix from $1,950 2025-01-24
Gdpr Ccpa Compliance \& Cookie Consent Banner HIGH 8.8
CVE-2025-24591

Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access …

Fix: 2.7.2+
Fix from $1,950 2025-01-24
Unclassified MEDIUM 6.5
CVE-2025-24594

Missing Authorization vulnerability in aribhour Linet ERP-Woocommerce Integration linet-erp-woocommerce-integration allows Exploiting Incorrectly Con…

Mitigation only
Fix from $1,600 2025-01-24
Woocommerce Product Table CRITICAL 9.8
CVE-2025-24596

Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite wc-product-table-lite allows Exploiting Incorrectly Configured…

Fix: 3.9.0+
Fix from $2,300 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24604

Missing Authorization vulnerability in Vikas Ratudi VPSUForm v-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified MEDIUM 6.5
CVE-2025-24580

Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Contr…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified MEDIUM 6.5
CVE-2025-24588

Missing Authorization vulnerability in patreon Patreon WordPress patreon-connect allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24571

Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Exploiting Incorrectly Configured Access Control Secur…

Mitigation only
Fix from $1,600 2025-01-24
Coolify CRITICAL 10.0
CVE-2025-22609

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing auth…

Fix: 4.0.0+
Fix from $2,300 2025-01-24
Coolify MEDIUM 6.5
CVE-2025-22610

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing auth…

Fix: 4.0.0+
Fix from $1,600 2025-01-24
Coolify CRITICAL 9.9
CVE-2025-22611

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing auth…

Fix: 4.0.0+
Fix from $2,300 2025-01-24
Coolify CRITICAL 10.0
CVE-2025-22612

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing auth…

Fix: 4.0.0+
Fix from $2,300 2025-01-24
Coolify MEDIUM 6.5
CVE-2025-22608

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing auth…

Fix: 4.0.0+
Fix from $1,600 2025-01-24
Coolify MEDIUM 5.5
CVE-2025-22607

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing auth…

Fix: 4.0.0+
Fix from $1,600 2025-01-24
Jobify MEDIUM 6.5
CVE-2024-13698

The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check …

Fix: after 4.2.7
Fix from $1,600 2025-01-24
Unclassified HIGH 7.5
CVE-2025-23512

Missing Authorization vulnerability in 118group Team 118GROUP Agent team-118group-agent allows Exploiting Incorrectly Configured Access Control Secur…

Mitigation only
Fix from $1,950 2025-01-22
Unclassified MEDIUM 6.5
CVE-2025-23486

Missing Authorization vulnerability in tamlyn Database Sync database-sync allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

Mitigation only
Fix from $1,600 2025-01-22
Aipower HIGH 8.8
CVE-2024-13361

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_m…

Fix: 1.8.97+
Fix from $1,950 2025-01-22
Jd Edwards Enterpriseone Tools MEDIUM 6.1
CVE-2025-21527

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design Tools SEC). Supported versions that are affected…

Fix: 9.2.9.0+
Fix from $1,600 2025-01-21
Jd Edwards Enterpriseone Tools MEDIUM 5.3
CVE-2025-21514

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …

Fix: 9.2.9.0+
Fix from $1,600 2025-01-21