Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-15475

The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validat…

Mitigation only
Fix from $1,600 2026-01-14
Unclassified MEDIUM 5.3
CVE-2025-15512

The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_suc…

Mitigation only
Fix from $1,600 2026-01-14
Unclassified MEDIUM 5.3
CVE-2025-14173

The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. This is due to missin…

Mitigation only
Fix from $1,600 2026-01-14
Unclassified MEDIUM 5.4
CVE-2025-14854

The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcrm_get_email_recipients and wp…

Mitigation only
Fix from $1,600 2026-01-14
Unclassified MEDIUM 5.3
CVE-2025-14880

The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mitigation only
Fix from $1,600 2026-01-14
Manageengine Pam360 HIGH 8.1
CVE-2025-11669

Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnera…

Fix: 4.4 / 8.2+
Fix from $1,950 2026-01-13
TYPO3 MEDIUM 6.4
CVE-2025-59021

Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect r…

Fix: 10.4.55 / 11.5.49+
Fix from $1,600 2026-01-13
TYPO3 HIGH 8.1
CVE-2025-59022

Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether th…

Fix: 10.4.55 / 11.5.49+
Fix from $1,950 2026-01-13
Unclassified MEDIUM 5.4
CVE-2025-14001

The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'duplicateBulkH…

Mitigation only
Fix from $1,600 2026-01-13
Netweaver Application Server Abap HIGH 8.1
CVE-2026-0506

Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC functi…

Patch available
Fix from $1,950 2026-01-13
Unclassified HIGH 8.1
CVE-2026-0511

SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation …

Mitigation only
Fix from $1,950 2026-01-13
Unclassified MEDIUM 6.4
CVE-2026-0503

Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcod…

Mitigation only
Fix from $1,600 2026-01-13
Unclassified MEDIUM 5.3
CVE-2025-14948

The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a…

Mitigation only
Fix from $1,600 2026-01-10
Campaignevents MEDIUM 5.3
CVE-2026-0817

Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki …

Patch available
Fix from $1,600 2026-01-09
Unclassified MEDIUM 6.5
CVE-2025-14172

The WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.4. This is due …

Mitigation only
Fix from $1,600 2026-01-09
Unclassified MEDIUM 5.3
CVE-2025-13717

The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_gvccf…

Mitigation only
Fix from $1,600 2026-01-09
GitLab MEDIUM 6.5
CVE-2025-13781

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could hav…

Fix: 18.5.5 / 18.6.3+
Fix from $1,600 2026-01-09
Unclassified MEDIUM 5.3
CVE-2025-14146

The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPB…

Mitigation only
Fix from $1,600 2026-01-09
Unclassified HIGH 7.2
CVE-2025-14657

The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data…

Mitigation only
Fix from $1,950 2026-01-09
Unclassified CRITICAL 9.1
CVE-2025-14741

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a …

Mitigation only
Fix from $2,300 2026-01-09
Unclassified MEDIUM 5.3
CVE-2025-14720

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks …

Mitigation only
Fix from $1,600 2026-01-09
Unclassified MEDIUM 5.3
CVE-2025-14782

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up…

Mitigation only
Fix from $1,600 2026-01-09
Unclassified MEDIUM 5.4
CVE-2025-14718

The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4…

Mitigation only
Fix from $1,600 2026-01-09
Unclassified MEDIUM 5.3
CVE-2025-14886

The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `order…

Mitigation only
Fix from $1,600 2026-01-09
Unclassified MEDIUM 6.5
CVE-2026-22522

Missing Authorization vulnerability in Munir Kamal Block Slider block-slider allows Exploiting Incorrectly Configured Access Control Security Levels.…

Mitigation only
Fix from $1,600 2026-01-08
Unclassified MEDIUM 5.3
CVE-2026-22488

Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beaver-builder allows Exploiting …

Mitigation only
Fix from $1,600 2026-01-08
Unclassified MEDIUM 5.4
CVE-2026-22490

Missing Authorization vulnerability in niklaslindemann Bulk Landing Page Creator for WordPress LPagery lpagery allows Exploiting Incorrectly Configur…

Mitigation only
Fix from $1,600 2026-01-08
Unclassified MEDIUM 5.4
CVE-2026-22517

Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Acc…

Mitigation only
Fix from $1,600 2026-01-08
Unclassified MEDIUM 5.3
CVE-2026-22486

Missing Authorization vulnerability in Re Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Re Galle…

No fix yet
Fix from $1,600 2026-01-08
Unclassified MEDIUM 5.3
CVE-2026-0676

Missing Authorization vulnerability in G5Theme Zorka zorka allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

No fix yet
Fix from $1,600 2026-01-08