Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.9
CVE-2026-27344

Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Mitigation only
Fix from $1,600 2026-03-05
Unclassified HIGH 7.5
CVE-2026-27361

Missing Authorization vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows Exploiting Incorrectly Confi…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified MEDIUM 6.5
CVE-2026-23799

Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

Mitigation only
Fix from $1,600 2026-03-05
Unclassified HIGH 7.5
CVE-2026-22479

Missing Authorization vulnerability in ThemeRuby Easy Post Submission easy-post-submission allows Exploiting Incorrectly Configured Access Control Se…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified MEDIUM 6.5
CVE-2026-22459

Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Configured Access Control Security…

Mitigation only
Fix from $1,600 2026-03-05
Unclassified HIGH 7.5
CVE-2025-69340

Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorre…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified MEDIUM 6.5
CVE-2026-2899

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is du…

Mitigation only
Fix from $1,600 2026-03-05
Unclassified MEDIUM 6.5
CVE-2026-1674

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to unauthorized…

Mitigation only
Fix from $1,600 2026-03-04
Unclassified MEDIUM 5.4
CVE-2026-2732

The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBa…

Patch available
Fix from $1,600 2026-03-04
Filr CRITICAL 9.8
CVE-2026-3266

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF t…

Fix: 25.1.3+
Fix from $2,300 2026-03-03
Engineering Requirements Management Doors Next MEDIUM 5.4
CVE-2025-13734

IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized acces…

Mitigation only
Fix from $1,600 2026-03-03
Unclassified MEDIUM 5.3
CVE-2026-1336

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to mi…

Mitigation only
Fix from $1,600 2026-03-03
Android HIGH 7.8
CVE-2026-0026

In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due to a logic error in the code…

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 7.3
CVE-2025-48634

In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escala…

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 8.4
CVE-2025-48574

In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission che…

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 7.8
CVE-2025-48578

In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permission chec…

Mitigation only
Fix from $1,950 2026-03-02
Sim CRITICAL 9.8
CVE-2026-3431

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or hos…

Fix: 0.5.74+
Fix from $2,300 2026-03-02
Sim CRITICAL 9.1
CVE-2026-3432

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided …

Fix: 0.5.74+
Fix from $2,300 2026-03-02
Wpforo Forum MEDIUM 5.4
CVE-2026-28556

wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split any forum topic via…

Fix: 2.4.16+
Fix from $1,600 2026-02-28
Wpforo Forum MEDIUM 6.5
CVE-2026-28557

wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment v…

Fix: 2.4.16+
Fix from $1,600 2026-02-28
Statamic MEDIUM 6.5
CVE-2026-28424

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in re…

Fix: 5.73.11 / 6.4.0+
Fix from $1,600 2026-02-27
Opendcim HIGH 8.8
CVE-2026-28515

openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The install…

Patch available
Fix from $1,950 2026-02-27
Wegia CRITICAL 9.8
CVE-2026-28408

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the pr…

Fix: 3.6.5+
Fix from $2,300 2026-02-27
Phpmyfaq HIGH 7.5
CVE-2026-27836

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active u…

Fix: 4.0.18+
Fix from $1,950 2026-02-27
Seerr MEDIUM 5.4
CVE-2026-27792

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified i…

Fix: 3.1.0+
Fix from $1,600 2026-02-27
Initiative HIGH 7.5
CVE-2026-28276

Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded…

Fix: 0.32.2+
Fix from $1,950 2026-02-26
Hoppscotch MEDIUM 6.5
CVE-2026-28217

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection…

Fix: 2026.2.0+
Fix from $1,600 2026-02-26
Actual HIGH 7.1
CVE-2026-27638

Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify …

Fix: 26.2.1+
Fix from $1,950 2026-02-26
Discourse MEDIUM 5.3
CVE-2026-27021

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoint in the poll plugin lacked p…

Fix: 2025.12.0 / 2026.1.1+
Fix from $1,600 2026-02-26
Discourse MEDIUM 5.4
CVE-2026-26207

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy` plugin allows any authentica…

Fix: 2025.12.0 / 2026.1.1+
Fix from $1,600 2026-02-26