Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Gogs MEDIUM 6.5
CVE-2026-23632

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write…

Fix: 0.13.4+
Fix from $1,600 2026-02-06
Unclassified HIGH 8.8
CVE-2026-1499

The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1…

Mitigation only
Fix from $1,950 2026-02-06
Unclassified MEDIUM 5.3
CVE-2025-10753

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14…

Mitigation only
Fix from $1,600 2026-02-06
Deploy HIGH 8.8
CVE-2025-15330

Tanium addressed an improper input validation vulnerability in Deploy.

Fix: 2.26.1279 / 2.30.175+
Fix from $1,950 2026-02-05
Unclassified MEDIUM 5.4
CVE-2026-1927

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec…

Mitigation only
Fix from $1,600 2026-02-05
Unclassified MEDIUM 5.3
CVE-2025-14079

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and includ…

Mitigation only
Fix from $1,600 2026-02-05
Devtron HIGH 8.8
CVE-2026-25538

Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists in Devtron's Attributes API in…

Fix: 2.0.0+
Fix from $1,950 2026-02-04
Unclassified MEDIUM 5.3
CVE-2026-0679

The Fortis for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an inverted nonce check in the 'check_fortis_notify_resp…

Mitigation only
Fix from $1,600 2026-02-04
Unclassified MEDIUM 5.3
CVE-2025-15507

The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Mitigation only
Fix from $1,600 2026-02-04
Unclassified MEDIUM 6.5
CVE-2026-0572

The WebPurify Profanity Filter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'webp…

Mitigation only
Fix from $1,600 2026-02-04
Unclassified MEDIUM 6.5
CVE-2025-15260

The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization in all versions up to, and inc…

Mitigation only
Fix from $1,600 2026-02-04
Unclassified HIGH 7.5
CVE-2025-15285

The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the checkBlog…

Mitigation only
Fix from $1,950 2026-02-04
Unclassified MEDIUM 5.3
CVE-2025-14461

The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, and including, 6.0.2. This is …

Mitigation only
Fix from $1,600 2026-02-04
Unclassified MEDIUM 5.4
CVE-2026-25028

Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Inco…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 6.5
CVE-2026-25036

Missing Authorization vulnerability in WP Chill Passster content-protector allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-25019

Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.4
CVE-2026-25021

Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control S…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-25010

Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Level…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-25012

Missing Authorization vulnerability in gfazioli WP Bannerize Pro wp-bannerize-pro allows Exploiting Incorrectly Configured Access Control Security Le…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.4
CVE-2026-24990

Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-24994

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Cont…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-24997

Missing Authorization vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Exploiting Incorrectly…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-24967

Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-24982

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 6.5
CVE-2026-24984

Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Configured Access Control Securit…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 6.5
CVE-2026-24957

Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Secur…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-24945

Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly C…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified HIGH 8.5
CVE-2025-13348

An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered by a local…

Mitigation only
Fix from $1,950 2026-02-02
Crmeb MEDIUM 5.3
CVE-2026-1734

A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/…

Fix: after 5.6.3
Fix from $1,600 2026-02-02
Unclassified MEDIUM 5.3
CVE-2026-1431

The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTI…

Mitigation only
Fix from $1,600 2026-01-31