Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Langfuse MEDIUM 5.3
CVE-2026-24055

Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates…

Fix: 3.147.0+
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.3
CVE-2026-1036

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c…

Mitigation only
Fix from $1,600 2026-01-22
Flux Operator MEDIUM 5.3
CVE-2026-23990

The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in…

Fix: 0.40.0+
Fix from $1,600 2026-01-21
Fleet HIGH 8.1
CVE-2026-23517

Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowe…

Fix: 4.53.3 / 4.75.2+
Fix from $1,950 2026-01-21
Unclassified MEDIUM 5.4
CVE-2026-0548

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized attachment deletion due to a missing capabili…

Mitigation only
Fix from $1,600 2026-01-20
Unclassified MEDIUM 5.4
CVE-2025-15043

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel…

Mitigation only
Fix from $1,600 2026-01-20
Unclassified HIGH 8.8
CVE-2025-15347

The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead t…

Mitigation only
Fix from $1,950 2026-01-20
Unclassified MEDIUM 5.3
CVE-2025-14351

The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '…

Mitigation only
Fix from $1,600 2026-01-20
Unclassified MEDIUM 5.3
CVE-2025-14798

The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.2.4 via the…

Mitigation only
Fix from $1,600 2026-01-20
Unclassified MEDIUM 5.3
CVE-2025-14978

The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for WordPress is vulnerable to una…

Mitigation only
Fix from $1,600 2026-01-20
Unclassified MEDIUM 5.4
CVE-2025-15466

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability…

Mitigation only
Fix from $1,600 2026-01-20
Crawlchat MEDIUM 5.4
CVE-2026-23875

CrawlChat is an open-source, AI-powered platform that transforms technical documentation into intelligent chatbots. Prior to version 0.0.8, a non-exi…

Fix: 0.0.8+
Fix from $1,600 2026-01-19
Prime HIGH 8.8
CVE-2026-1169

A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. Such manipulation leads to cr…

Fix: after 0.4.0
Fix from $1,950 2026-01-19
Patients Waiting Area Queue Management System MEDIUM 6.5
CVE-2026-1148

A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This vulnerability affects unknown …

Mitigation only
Fix from $1,600 2026-01-19
News Portal MEDIUM 6.5
CVE-2026-1142

A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in …

No fix yet
Fix from $1,600 2026-01-19
Unclassified MEDIUM 5.3
CVE-2025-14078

The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.6. This is due to m…

Mitigation only
Fix from $1,600 2026-01-17
Unclassified MEDIUM 5.3
CVE-2025-14029

The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_admin_even…

Mitigation only
Fix from $1,600 2026-01-17
Unclassified MEDIUM 5.3
CVE-2025-12825

The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the…

Mitigation only
Fix from $1,600 2026-01-17
Unclassified MEDIUM 5.3
CVE-2025-14463

The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This …

Mitigation only
Fix from $1,600 2026-01-17
Unclassified MEDIUM 6.5
CVE-2025-14450

The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'c…

Mitigation only
Fix from $1,600 2026-01-17
Unclassified MEDIUM 5.3
CVE-2026-1004

The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via…

Patch available
Fix from $1,600 2026-01-16
Cost Calculator Builder MEDIUM 5.3
CVE-2025-14757

The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 o…

Fix: 3.6.10+
Fix from $1,600 2026-01-16
Unclassified MEDIUM 6.5
CVE-2026-1000

The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deletion in all versions up to, and…

Mitigation only
Fix from $1,600 2026-01-16
Unclassified MEDIUM 6.5
CVE-2025-12641

The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all…

Mitigation only
Fix from $1,600 2026-01-16
Process Optimization HIGH 8.2
CVE-2025-64729

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed…

Fix: 2025+
Fix from $1,950 2026-01-16
Grav CRITICAL 9.8
CVE-2021-47812

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code thro…

Mitigation only
Fix from $2,300 2026-01-16
Unclassified MEDIUM 6.4
CVE-2025-13859

The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on…

Mitigation only
Fix from $1,600 2026-01-15
Unclassified MEDIUM 5.3
CVE-2025-12895

The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending due to a missing capability che…

Mitigation only
Fix from $1,600 2026-01-15
Contact Form 7 HIGH 7.4
CVE-2025-14457

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ow…

Fix: after 1.3.9.2
Fix from $1,950 2026-01-15
Rocket.chat MEDIUM 6.5
CVE-2026-23477

Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1…

Fix: 6.12.0+
Fix from $1,600 2026-01-14