Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 8.8
CVE-2019-25351

Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary system files through the server.…

No fix yet
Fix from $1,950 2026-02-18
Enterprise Server MEDIUM 6.5
CVE-2026-1355

A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another u…

Fix: 3.14.23 / 3.15.18+
Fix from $1,600 2026-02-18
Membership Management System CRITICAL 9.8
CVE-2025-70150

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attacker…

Mitigation only
Fix from $2,300 2026-02-18
Membership Management System HIGH 7.5
CVE-2025-70148

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers …

No fix yet
Fix from $1,950 2026-02-18
Online Time Table Generator HIGH 7.5
CVE-2025-70147

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtai…

No fix yet
Fix from $1,950 2026-02-18
Customer Support System CRITICAL 9.4
CVE-2025-70141

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authe…

No fix yet
Fix from $2,300 2026-02-18
Online Time Table Generator CRITICAL 9.1
CVE-2025-70146

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attacke…

No fix yet
Fix from $2,300 2026-02-18
Unclassified MEDIUM 6.5
CVE-2026-1942

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili…

Mitigation only
Fix from $1,600 2026-02-18
Unclassified MEDIUM 5.3
CVE-2026-1656

The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check in all versions up to, and inc…

Mitigation only
Fix from $1,600 2026-02-18
Unclassified MEDIUM 5.4
CVE-2026-2127

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all versions up to, and including, …

Mitigation only
Fix from $1,600 2026-02-18
Unclassified MEDIUM 5.3
CVE-2026-1938

The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized license key deletion due to a missing authorization che…

Mitigation only
Fix from $1,600 2026-02-18
Unclassified HIGH 7.2
CVE-2026-1937

The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat…

Mitigation only
Fix from $1,950 2026-02-18
Unclassified MEDIUM 6.5
CVE-2024-31118

Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2026-02-17
Unclassified MEDIUM 6.5
CVE-2022-41650

Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.This issue affects Custom Conten…

Mitigation only
Fix from $1,600 2026-02-17
Nifi MEDIUM 6.6
CVE-2026-25903

Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required …

Fix: 2.8.0+
Fix from $1,600 2026-02-17
Unclassified MEDIUM 5.8
CVE-2026-0829

The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security chec…

Mitigation only
Fix from $1,600 2026-02-17
Unclassified MEDIUM 5.3
CVE-2026-1657

The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the…

Mitigation only
Fix from $1,600 2026-02-17
Unclassified HIGH 8.8
CVE-2026-2001

The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activ…

Mitigation only
Fix from $1,950 2026-02-16
Enet Smart Home HIGH 8.1
CVE-2026-26367

eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authe…

No fix yet
Fix from $1,950 2026-02-15
Enet Smart Home HIGH 8.8
CVE-2026-26368

eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword JSON-RPC method that allows any authen…

No fix yet
Fix from $1,950 2026-02-15
Unclassified MEDIUM 5.3
CVE-2026-1944

The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cb…

Mitigation only
Fix from $1,600 2026-02-14
Unclassified MEDIUM 5.3
CVE-2026-1303

The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.2.4. This is due to missi…

Mitigation only
Fix from $1,600 2026-02-14
Unclassified MEDIUM 5.4
CVE-2026-0727

The Accordion and Accordion Slider plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.5. This is du…

Mitigation only
Fix from $1,600 2026-02-14
Unclassified MEDIUM 5.3
CVE-2026-1932

The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c…

Mitigation only
Fix from $1,600 2026-02-14
Unclassified HIGH 7.5
CVE-2026-0692

The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0.…

Mitigation only
Fix from $1,950 2026-02-14
Unclassified MEDIUM 5.3
CVE-2025-14067

The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in…

Mitigation only
Fix from $1,600 2026-02-14
Unclassified MEDIUM 5.3
CVE-2025-14608

The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.5. This is…

Patch available
Fix from $1,600 2026-02-14
Unclassified HIGH 8.8
CVE-2025-15157

The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to pri…

Mitigation only
Fix from $1,950 2026-02-13
Cursor CRITICAL 9.9
CVE-2026-26268

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicio…

Fix: 2.5+
Fix from $2,300 2026-02-13
Lavinmq MEDIUM 6.5
CVE-2026-25768

LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should n…

Fix: 2.6.6+
Fix from $1,600 2026-02-12