Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 7.5
CVE-2026-61954

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-61972

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2026-59547

Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.5
CVE-2026-61943

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-59522

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-57808

Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.3
CVE-2026-57703

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-57717

Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-57425

Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.1
CVE-2026-57367

Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.7
CVE-2026-27377

Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-27391

Subscriber Broken Access Control in uListing <= 2.2.0 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-27399

Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-27418

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-27422

Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-27355

Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-25427

Subscriber Broken Access Control in eRoom <= 1.7.1 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-25466

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-15827

The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/m…

No fix yet
Fix from $1,600 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-15015

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. T…

Mitigation only
Fix from $2,300 2026-07-23
Unclassified MEDIUM 6.8
CVE-2026-59677

A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-own…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2026-12082

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated us…

No fix yet
Fix from $1,950 2026-07-23
MongoDB HIGH 7.7
CVE-2026-13078

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that e…

No fix yet
Fix from $1,950 2026-07-22
Unclassified MEDIUM 6.8
CVE-2026-7328

Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.5
CVE-2026-16544

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access…

No fix yet
Fix from $1,600 2026-07-22
Kibana MEDIUM 5.4
CVE-2026-63141

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without …

Fix: 9.3.8 / 9.4.4+
Fix from $1,600 2026-07-21
Human Capital Management Configuration Workbench HIGH 7.3
CVE-2026-61267

Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that…

No fix yet
Fix from $1,950 2026-07-21
Telecommunications Billing Integrator HIGH 8.1
CVE-2026-60953

Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported ver…

Fix: after 12.2.15
Fix from $1,950 2026-07-21
Siebel Crm MEDIUM 6.5
CVE-2026-60712

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affec…

Fix: after 26.5
Fix from $1,600 2026-07-21
Unclassified MEDIUM 5.3
CVE-2026-65055

Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal wor…

No fix yet
Fix from $1,600 2026-07-21