Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2025-67926

Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security…

Mitigation only
Fix from $1,600 2026-01-08
Unclassified MEDIUM 6.5
CVE-2025-67913

Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained b…

Mitigation only
Fix from $1,600 2026-01-08
Unclassified MEDIUM 6.5
CVE-2025-67917

Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Mitigation only
Fix from $1,600 2026-01-08
Unclassified HIGH 7.5
CVE-2025-22715

Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Exp…

Mitigation only
Fix from $1,950 2026-01-08
Unclassified HIGH 7.5
CVE-2025-14360

Missing Authorization vulnerability in Kaira Blockons blockons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blo…

Mitigation only
Fix from $1,950 2026-01-08
Unclassified HIGH 7.5
CVE-2025-14358

Missing Authorization vulnerability in sizam REHub Framework rehub-framework allows Accessing Functionality Not Properly Constrained by ACLs.This iss…

Mitigation only
Fix from $1,950 2026-01-08
Unclassified MEDIUM 6.5
CVE-2025-13679

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch…

Mitigation only
Fix from $1,600 2026-01-08
Librechat MEDIUM 5.9
CVE-2025-69220

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file co…

Patch available
Fix from $1,600 2026-01-07
Unclassified MEDIUM 6.5
CVE-2025-46434

Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon allows Exploiting Incorrectly Co…

Mitigation only
Fix from $1,600 2026-01-07
Chrome HIGH 8.8
CVE-2026-0628EPSS 7%

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicio…

Fix: 143.0.7499.192+
Fix from $1,950 2026-01-07
Unclassified HIGH 8.2
CVE-2026-0656

The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2.0.2 v…

Mitigation only
Fix from $1,950 2026-01-07
Unclassified MEDIUM 6.5
CVE-2025-14901

The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerW…

Mitigation only
Fix from $1,600 2026-01-07
Unclassified MEDIUM 5.3
CVE-2025-14460

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modification in all versions up to, and …

Mitigation only
Fix from $1,600 2026-01-07
Unclassified HIGH 7.5
CVE-2025-14070

The Reviewify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'send_test_email' AJAX…

Mitigation only
Fix from $1,950 2026-01-07
Unclassified MEDIUM 5.3
CVE-2025-13529

The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'init' action in all versi…

Mitigation only
Fix from $1,600 2026-01-07
Unclassified MEDIUM 5.3
CVE-2025-13722

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorizatio…

Mitigation only
Fix from $1,600 2026-01-07
Unclassified HIGH 7.5
CVE-2025-13493

The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, and including, 1.4. This is du…

Mitigation only
Fix from $1,950 2026-01-07
Unclassified MEDIUM 5.3
CVE-2025-13496

The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the moosend_la…

Mitigation only
Fix from $1,600 2026-01-07
Unclassified MEDIUM 5.3
CVE-2025-13419

The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unauthorized modification of data du…

Mitigation only
Fix from $1,600 2026-01-07
Unclassified HIGH 7.5
CVE-2025-11877

The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_…

Mitigation only
Fix from $1,950 2026-01-07
Unclassified MEDIUM 5.4
CVE-2025-12449

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive informat…

Mitigation only
Fix from $1,600 2026-01-07
Unclassified MEDIUM 5.3
CVE-2025-69364

Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

Mitigation only
Fix from $1,600 2026-01-06
Unclassified MEDIUM 5.3
CVE-2025-69359

Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This …

No fix yet
Fix from $1,600 2026-01-06
Unclassified MEDIUM 6.5
CVE-2025-69363

Missing Authorization vulnerability in CyberChimps Responsive Addons for Elementor responsive-addons-for-elementor allows Exploiting Incorrectly Conf…

Mitigation only
Fix from $1,600 2026-01-06
Unclassified MEDIUM 5.4
CVE-2025-69349

Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Configured Access Control Security…

Mitigation only
Fix from $1,600 2026-01-06
Unclassified MEDIUM 5.4
CVE-2025-69352

Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Secu…

No fix yet
Fix from $1,600 2026-01-06
Unclassified MEDIUM 5.4
CVE-2025-69341

Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorre…

Mitigation only
Fix from $1,600 2026-01-06
Unclassified CRITICAL 9.8
CVE-2025-39477

Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

Mitigation only
Fix from $2,300 2026-01-06
Quiz And Survey Master MEDIUM 6.5
CVE-2025-9637

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due …

Fix: 10.3.2+
Fix from $1,600 2026-01-06
Unclassified MEDIUM 5.3
CVE-2025-13964

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th…

Mitigation only
Fix from $1,600 2026-01-06