Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2026-39509

Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-39520

Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-39501

Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security …

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-39504

Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Level…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-39505

Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured …

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39488

Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-3477

The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. The pzfm_user_request_…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-3480

The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. The plugin registers an admin…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-3646

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all ver…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified CRITICAL 9.8
CVE-2026-4003

The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including …

Mitigation only
Fix from $2,300 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-4299

The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a miss…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-2263

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missin…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-4065

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp…

Mitigation only
Fix from $1,600 2026-04-07
Payload Puck CRITICAL 9.8
CVE-2026-39397

@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers…

Fix: 0.6.23+
Fix from $2,300 2026-04-07
Cronicle MEDIUM 5.4
CVE-2026-39401

Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event…

Fix: 0.9.111+
Fix from $1,600 2026-04-07
Frappe CRITICAL 9.1
CVE-2026-39351

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.

Fix: 15.104.0 / 16.14.0+
Fix from $2,300 2026-04-07
Genealogy HIGH 8.8
CVE-2026-39355

Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any au…

Fix: 5.9.1+
Fix from $1,950 2026-04-07
Openviking MEDIUM 5.3
CVE-2026-22680

OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to …

Fix: 0.3.3+
Fix from $1,600 2026-04-07
Filebrowser HIGH 7.5
CVE-2026-35606

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Fix: after 2.63.0
Fix from $1,950 2026-04-07
Flow HIGH 8.8
CVE-2026-22683

Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited…

Fix: after 1.614.0
Fix from $1,950 2026-04-07
Unclassified MEDIUM 5.3
CVE-2025-14944

The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missin…

Mitigation only
Fix from $1,600 2026-04-07
Django CRITICAL 9.8
CVE-2026-4277

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated o…

Fix: 4.2.30 / 5.2.13+
Fix from $2,300 2026-04-07
Unclassified MEDIUM 5.3
CVE-2026-34899

Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Acc…

Mitigation only
Fix from $1,600 2026-04-07
Unclassified MEDIUM 5.4
CVE-2026-34903

Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

Mitigation only
Fix from $1,600 2026-04-07
Avideo MEDIUM 5.3
CVE-2026-35179

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoin…

Fix: after 26.0
Fix from $1,600 2026-04-06
Bravecms HIGH 8.8
CVE-2026-35182

Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.…

Fix: 2.0.6+
Fix from $1,950 2026-04-06
Ajenti MEDIUM 6.5
CVE-2026-35175

Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) coul…

Fix: 2.2.15+
Fix from $1,600 2026-04-06
Dgraph CRITICAL 10.0
CVE-2026-34976

Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware…

Fix: after 25.3.0
Fix from $2,300 2026-04-06
Twitch Studio HIGH 7.8
CVE-2024-14032

Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to exe…

Fix: after 0.114.8
Fix from $1,950 2026-04-06
Legal Hold HIGH 8.8
CVE-2026-3524

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authent…

Fix: 1.1.5+
Fix from $1,950 2026-04-06