Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HTTP Server MEDIUM 5.3
CVE-2025-21498

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0…

Mitigation only
Fix from $1,600 2025-01-21
Teamcity MEDIUM 6.5
CVE-2025-24461

In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint

Mitigation only
Fix from $1,600 2025-01-21
Unclassified HIGH 8.2
CVE-2025-23477

Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Functionality Not Properly Constraine…

Mitigation only
Fix from $1,950 2025-01-21
Unclassified HIGH 7.5
CVE-2025-22717

Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Accessing Functionality Not Properly Constrained by ACLs.This issue af…

Mitigation only
Fix from $1,950 2025-01-21
Unclassified HIGH 7.5
CVE-2025-22318

Missing Authorization vulnerability in enituretechnology Standard Box Sizes – for WooCommerce standard-box-sizes.This issue affects Standard Box Size…

Mitigation only
Fix from $1,950 2025-01-21
Atarim HIGH 7.5
CVE-2024-12104

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a mis…

Fix: 4.1.0+
Fix from $1,950 2025-01-21
Evergreen Content Poster MEDIUM 5.3
CVE-2024-12071

The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of da…

Fix: 1.4.5+
Fix from $1,600 2025-01-18
Android MEDIUM 5.5
CVE-2018-9406

In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privi…

Mitigation only
Fix from $1,600 2025-01-18
Android HIGH 7.8
CVE-2018-9382

In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission…

Mitigation only
Fix from $1,950 2025-01-17
Unclassified MEDIUM 6.5
CVE-2024-50967

The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely acc…

Mitigation only
Fix from $1,600 2025-01-17
Wp Hotel Booking MEDIUM 5.3
CVE-2024-12370

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in a…

Fix: 2.1.6+
Fix from $1,600 2025-01-17
Unclassified MEDIUM 6.5
CVE-2024-13367

The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_download action in all versions…

Mitigation only
Fix from $1,600 2025-01-17
Ac6 Firmware HIGH 8.1
CVE-2024-46450

Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication v…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified MEDIUM 5.4
CVE-2025-23961

Missing Authorization vulnerability in wptasker WordPress Graphs & Charts graph-lite allows Exploiting Incorrectly Configured Access Control Security…

Mitigation only
Fix from $1,600 2025-01-16
Unclassified MEDIUM 5.4
CVE-2025-23963

Missing Authorization vulnerability in flymke Mark Posts mark-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Mitigation only
Fix from $1,600 2025-01-16
Unclassified MEDIUM 5.4
CVE-2025-23916

Missing Authorization vulnerability in Nuanced Media WP Meetup wp-meetup allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Mitigation only
Fix from $1,600 2025-01-16
Unclassified MEDIUM 5.4
CVE-2025-23917

Missing Authorization vulnerability in Chandrika Guntur, Morgan Kay Chamber Dashboard Business Directory allows Exploiting Incorrectly Configured Acc…

Mitigation only
Fix from $1,600 2025-01-16
Unclassified MEDIUM 5.3
CVE-2025-23862

Missing Authorization vulnerability in SzMake Contact Form 7 Anti Spambot contact-form-7-anti-spambot allows Exploiting Incorrectly Configured Access…

Mitigation only
Fix from $1,600 2025-01-16
Unclassified MEDIUM 5.4
CVE-2025-23778

Missing Authorization vulnerability in Pravin Durugkar User Sync ActiveCampaign registered-user-sync-activecampaign allows Exploiting Incorrectly Con…

Mitigation only
Fix from $1,600 2025-01-16
Unclassified MEDIUM 5.4
CVE-2025-23761

Missing Authorization vulnerability in Alex Volkov Woo Tuner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affe…

Mitigation only
Fix from $1,600 2025-01-16
Unclassified MEDIUM 5.3
CVE-2025-23764

Missing Authorization vulnerability in ujjavaljani Copy Move Posts copy-move-posts.This issue affects Copy Move Posts: from n/a through <= 1.6.

No fix yet
Fix from $1,600 2025-01-16
Unclassified MEDIUM 5.3
CVE-2025-23514

Missing Authorization vulnerability in Sanjay Prasad Loginplus loginplus allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…

Mitigation only
Fix from $1,600 2025-01-16
Dir 816 Firmware MEDIUM 6.5
CVE-2024-57682

An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to a…

Mitigation only
Fix from $1,600 2025-01-16
Multi Step Form MEDIUM 5.3
CVE-2024-12427

The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJ…

Fix: 1.7.24+
Fix from $1,600 2025-01-16
Simplehelp CRITICAL 9.9
CVE-2024-57726 KEVEPSS 67%

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive per…

Fix: 5.5.8+
Fix from $2,300 2025-01-15
Button Block HIGH 8.8
CVE-2025-22787

Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue …

Fix: 1.1.6+
Fix from $1,950 2025-01-15
Unclassified MEDIUM 5.3
CVE-2025-22737

Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Accessing Functionality Not Properly Constrained by ACLs…

Mitigation only
Fix from $1,600 2025-01-15
Poll Maker MEDIUM 6.5
CVE-2024-56295

Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Fix: 5.5.7+
Fix from $1,600 2025-01-15
Unclassified HIGH 8.1
CVE-2024-11848

The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_not…

Mitigation only
Fix from $1,950 2025-01-15
Jeewms HIGH 7.5
CVE-2024-57757

JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.

Fix: 2025.01.01+
Fix from $1,950 2025-01-15