Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 8.8
CVE-2026-1104

The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missi…

Mitigation only
Fix from $1,950 2026-02-12
Unclassified MEDIUM 6.5
CVE-2026-1671

The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the winter_acti…

Mitigation only
Fix from $1,600 2026-02-12
Unclassified MEDIUM 5.3
CVE-2026-1537

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missin…

Mitigation only
Fix from $1,600 2026-02-12
Ipados HIGH 7.8
CVE-2026-20626

This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3…

Fix: 15.7.4 / 26.3+
Fix from $1,950 2026-02-11
Unclassified MEDIUM 5.8
CVE-2025-13391

The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to unauthorized loss of dat…

Mitigation only
Fix from $1,600 2026-02-11
GitLab MEDIUM 5.3
CVE-2025-14592

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under…

Fix: 18.6.6 / 18.7.4+
Fix from $1,600 2026-02-11
Unclassified MEDIUM 5.3
CVE-2026-1833

The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0.1. This i…

Mitigation only
Fix from $1,600 2026-02-11
Unclassified MEDIUM 6.5
CVE-2026-1786

The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dg_tw_opt…

Mitigation only
Fix from $1,600 2026-02-11
Unclassified MEDIUM 6.5
CVE-2025-15400

The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configur…

Mitigation only
Fix from $1,600 2026-02-11
Fortiauthenticator HIGH 7.2
CVE-2026-21743

A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4…

Fix: 6.6.7+
Fix from $1,950 2026-02-10
Unclassified MEDIUM 5.4
CVE-2025-14895

The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. This is due to the plugin not pr…

Mitigation only
Fix from $1,600 2026-02-10
Unclassified MEDIUM 5.3
CVE-2026-1722

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions…

Mitigation only
Fix from $1,600 2026-02-10
Solution Tools Plug In HIGH 7.7
CVE-2026-24322

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allow…

Mitigation only
Fix from $1,950 2026-02-10
Sap Basis MEDIUM 5.2
CVE-2026-24312

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restric…

Mitigation only
Fix from $1,600 2026-02-10
Netweaver As Abap Kernel CRITICAL 9.6
CVE-2026-0509

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls with…

Mitigation only
Fix from $2,300 2026-02-10
Netweaver Application Server Abap CRITICAL 9.9
CVE-2026-0488

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz…

Mitigation only
Fix from $2,300 2026-02-10
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2026-0490

SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authen…

Mitigation only
Fix from $1,950 2026-02-10
Sap Basis MEDIUM 6.5
CVE-2026-0484

Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa…

Mitigation only
Fix from $1,600 2026-02-10
Unclassified HIGH 7.2
CVE-2026-0845

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized m…

Mitigation only
Fix from $1,950 2026-02-10
Fuxa CRITICAL 9.1
CVE-2026-25939EPSS 11%

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability i…

Fix: 1.2.11+
Fix from $2,300 2026-02-09
Hollo HIGH 7.5
CVE-2026-25808

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security …

Fix: 0.6.20 / 0.7.2+
Fix from $1,950 2026-02-09
Placipy CRITICAL 9.1
CVE-2026-25810

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts…

Mitigation only
Fix from $2,300 2026-02-09
Placipy CRITICAL 9.1
CVE-2026-25876

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify aut…

Mitigation only
Fix from $2,300 2026-02-09
Placipy MEDIUM 6.5
CVE-2026-25806

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/:email PUT /api/students/:ema…

Mitigation only
Fix from $1,600 2026-02-09
Openproject MEDIUM 6.7
CVE-2026-24777

OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permission can lock and unlock use…

Fix: 17.0.2+
Fix from $1,600 2026-02-09
Unclassified MEDIUM 5.3
CVE-2026-24095

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" pe…

Mitigation only
Fix from $1,600 2026-02-09
Wekan MEDIUM 6.5
CVE-2026-2208

A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the compo…

Fix: 8.21+
Fix from $1,600 2026-02-08
Smart Pixelator Firmware HIGH 8.8
CVE-2026-2065

A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Blu…

No fix yet
Fix from $1,950 2026-02-06
Fuxa CRITICAL 9.1
CVE-2026-25752

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, re…

Fix: 1.2.10+
Fix from $2,300 2026-02-06
Gogs MEDIUM 6.5
CVE-2026-22592

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files i…

Fix: 0.13.4+
Fix from $1,600 2026-02-06