Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2025-5919

The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access and modification of da…

Mitigation only
Fix from $1,600 2026-01-06
Unclassified MEDIUM 5.4
CVE-2025-13766

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion …

Mitigation only
Fix from $1,600 2026-01-06
Unclassified MEDIUM 5.3
CVE-2025-14034

The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capabili…

Mitigation only
Fix from $1,600 2026-01-06
Unclassified MEDIUM 5.3
CVE-2025-11370

The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel…

Mitigation only
Fix from $1,600 2026-01-06
Unclassified MEDIUM 6.5
CVE-2025-39561

Missing Authorization vulnerability in Marketing Fire, LLC LoginWP - Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…

Mitigation only
Fix from $1,600 2026-01-05
Unclassified HIGH 7.5
CVE-2025-46255

Missing Authorization vulnerability in Marketing Fire LLC LoginWP - Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue af…

Mitigation only
Fix from $1,950 2026-01-05
Unclassified HIGH 7.5
CVE-2025-68850

Missing Authorization vulnerability in codepeople Sell Downloads sell-downloads allows Exploiting Incorrectly Configured Access Control Security Leve…

Mitigation only
Fix from $1,950 2026-01-05
Follow My Blog Post HIGH 7.5
CVE-2025-68547

Missing Authorization vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Exploiting Incorrectly Configured Access Control Security…

Fix: 2.4.1+
Fix from $1,950 2026-01-05
Centreon Web MEDIUM 5.3
CVE-2025-12519

Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not …

Fix: 24.04.19 / 24.10.15+
Fix from $1,600 2026-01-05
Qoca Aim MEDIUM 6.5
CVE-2025-15235

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing authenticated remote attackers to…

Fix: 2.7.6+
Fix from $1,600 2026-01-05
Petlibro CRITICAL 9.8
CVE-2025-15115

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to acc…

Fix: after 1.7.31
Fix from $2,300 2026-01-04
Casaos MEDIUM 5.3
CVE-2025-34171

CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration …

Fix: after 0.4.15
Fix from $1,600 2026-01-02
Unclassified MEDIUM 5.3
CVE-2025-14047

The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress…

Mitigation only
Fix from $1,600 2026-01-02
Online Course Registration HIGH 8.8
CVE-2025-15406

A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authoriz…

Fix: after 3.1
Fix from $1,950 2026-01-01
Phpems HIGH 8.8
CVE-2025-15405

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forger…

Fix: after 11.0
Fix from $1,950 2026-01-01
Unclassified MEDIUM 5.4
CVE-2025-66144

Missing Authorization vulnerability in merkulove Worker for Elementor worker-elementor allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66145

Missing Authorization vulnerability in merkulove Worker for WPBakery worker-wpbakery allows Exploiting Incorrectly Configured Access Control Security…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66146

Missing Authorization vulnerability in merkulove Logger for Elementor logger-elementor allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66148

Missing Authorization vulnerability in merkulove Conformer for Elementor conformer-elementor allows Exploiting Incorrectly Configured Access Control …

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66149

Missing Authorization vulnerability in merkulove UnGrabber ungrabber allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66150

Missing Authorization vulnerability in merkulove Appender appender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66151

Missing Authorization vulnerability in merkulove Countdowner for Elementor countdowner-elementor allows Exploiting Incorrectly Configured Access Cont…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66152

Missing Authorization vulnerability in merkulove Criptopayer for Elementor criptopayer-elementor allows Exploiting Incorrectly Configured Access Cont…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66153

Missing Authorization vulnerability in merkulove Headinger for Elementor headinger-elementor allows Exploiting Incorrectly Configured Access Control …

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66158

Missing Authorization vulnerability in merkulove Gmaper for Elementor gmaper-elementor allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66159

Missing Authorization vulnerability in merkulove Walker for Elementor walker-elementor allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66160

Missing Authorization vulnerability in merkulove Select Graphist for Elementor Graphist for Elementor graphist-elementor allows Exploiting Incorrect…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66155

Missing Authorization vulnerability in merkulove Questionar for Elementor questionar-elementor allows Exploiting Incorrectly Configured Access Contro…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66156

Missing Authorization vulnerability in merkulove Watcher for Elementor watcher-elementor allows Exploiting Incorrectly Configured Access Control Secu…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-66157

Missing Authorization vulnerability in merkulove Sliper for Elementor sliper-elementor allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,600 2025-12-31