Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Cx7 Firmware MEDIUM 5.3
CVE-2026-35061

Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication, revealing sensitive operatio…

Mitigation only
Fix from $1,600 2026-04-17
Cx7 Firmware MEDIUM 5.3
CVE-2026-32648

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/RTTY status), assisting attack…

Mitigation only
Fix from $1,600 2026-04-17
Cx7 Firmware MEDIUM 5.3
CVE-2026-33093

Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing camera, exposing visual inform…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified MEDIUM 5.3
CVE-2026-5502

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified MEDIUM 5.3
CVE-2026-5427

The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability c…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified MEDIUM 6.5
CVE-2026-4666

The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-c…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified MEDIUM 6.5
CVE-2026-3488

The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing c…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified MEDIUM 5.9
CVE-2026-40265

Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/notes/{noteID}/assets/{assetID…

Patch available
Fix from $1,600 2026-04-17
Unclassified MEDIUM 5.3
CVE-2026-0718

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized modification of data due…

Mitigation only
Fix from $1,600 2026-04-16
Unclassified HIGH 8.8
CVE-2026-3614

The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and including, 10.8.1 due to a missing c…

Mitigation only
Fix from $1,950 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-3596

The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin regis…

Mitigation only
Fix from $2,300 2026-04-16
Unclassified MEDIUM 5.3
CVE-2026-3595

The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to t…

Mitigation only
Fix from $1,600 2026-04-16
Unclassified MEDIUM 5.3
CVE-2026-3581

The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to …

Mitigation only
Fix from $1,600 2026-04-16
Openharness HIGH 8.8
CVE-2026-40502

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive …

Fix: 2026-04-13+
Fix from $1,950 2026-04-16
Unclassified HIGH 7.5
CVE-2026-6372

Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configured Access Control Security Le…

Mitigation only
Fix from $1,950 2026-04-15
Unclassified CRITICAL 9.3
CVE-2026-5387

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator D…

Mitigation only
Fix from $2,300 2026-04-15
Unclassified MEDIUM 5.4
CVE-2026-40740

Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.3
CVE-2026-40742

Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Configured Access Control Secur…

No fix yet
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.3
CVE-2026-40763

Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.3
CVE-2026-40778

Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.3
CVE-2026-40730

Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access C…

No fix yet
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.3
CVE-2026-3642

The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builde…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.3
CVE-2026-3649

The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.0. The katalogportal_p…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.3
CVE-2026-4812

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and …

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.3
CVE-2026-1314

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to …

Mitigation only
Fix from $1,600 2026-04-15
Jellyfin CRITICAL 9.1
CVE-2026-35033

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpe…

Fix: 10.11.7+
Fix from $2,300 2026-04-14
Unclassified MEDIUM 5.3
CVE-2025-15565

The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in…

Mitigation only
Fix from $1,600 2026-04-14
Fortisoar HIGH 8.1
CVE-2026-23708

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.…

Fix: 7.5.3 / 7.6.4+
Fix from $1,950 2026-04-14
Unclassified CRITICAL 9.1
CVE-2026-4365

The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` f…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified HIGH 7.1
CVE-2026-34256

Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular …

Mitigation only
Fix from $1,950 2026-04-14