Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-14365

The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to…

Mitigation only
Fix from $1,600 2025-12-13
Unclassified MEDIUM 5.3
CVE-2025-14366

The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to…

Mitigation only
Fix from $1,600 2025-12-13
Unclassified MEDIUM 5.3
CVE-2025-14367

The Easy Theme Options plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0. This is due to missing …

Mitigation only
Fix from $1,600 2025-12-13
Unclassified MEDIUM 5.3
CVE-2025-13093

The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized modification of data due to a missi…

Mitigation only
Fix from $1,600 2025-12-13
Unclassified MEDIUM 5.3
CVE-2025-12362

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorizatio…

Mitigation only
Fix from $1,600 2025-12-13
Unclassified MEDIUM 5.3
CVE-2025-13092

The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized access of data due to a missing cap…

Mitigation only
Fix from $1,600 2025-12-13
macOS MEDIUM 5.2
CVE-2025-43497

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to break out of its s…

Fix: 26.1+
Fix from $1,600 2025-12-12
Unclassified MEDIUM 5.3
CVE-2025-12655

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up…

Mitigation only
Fix from $1,600 2025-12-12
Unclassified MEDIUM 5.4
CVE-2025-14064

The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple AJAX e…

Mitigation only
Fix from $1,600 2025-12-12
Unclassified MEDIUM 6.4
CVE-2025-13866

The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flo…

Mitigation only
Fix from $1,600 2025-12-12
Unclassified HIGH 8.1
CVE-2025-13334

The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the…

Mitigation only
Fix from $1,950 2025-12-12
Unclassified MEDIUM 5.3
CVE-2025-13440

The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This…

Mitigation only
Fix from $1,600 2025-12-12
Unclassified CRITICAL 9.8
CVE-2025-12963

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via a…

Mitigation only
Fix from $2,300 2025-12-12
Unclassified MEDIUM 5.3
CVE-2025-13314

The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for WordPress is vulnerable to unauthorized modification …

Mitigation only
Fix from $1,600 2025-12-12
Medivision Digital Signage Firmware CRITICAL 9.8
CVE-2020-36902

UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulatin…

Mitigation only
Fix from $2,300 2025-12-10
Sft Dab 015\/c Firmware CRITICAL 9.8
CVE-2023-53740

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current…

Mitigation only
Fix from $2,300 2025-12-10
Openbmcs HIGH 8.8
CVE-2021-47701

OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability i…

No fix yet
Fix from $1,950 2025-12-09
Unclassified MEDIUM 5.4
CVE-2023-23729

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2022-46845

Missing Authorization vulnerability in Essential Plugin Slider a SlidersPack allows Exploiting Incorrectly Configured Access Control Security Levels.…

Mitigation only
Fix from $1,600 2025-12-09
Armember HIGH 8.8
CVE-2022-47425

Missing Authorization vulnerability in Repute Infosystems ARMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

Fix: 3.4.11+
Fix from $1,950 2025-12-09
Idonate MEDIUM 5.3
CVE-2025-67583

Missing Authorization vulnerability in Foysal Imran IDonate idonate allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Fix: 2.1.16+
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-67584

Missing Authorization vulnerability in rtCamp GoDAM godam allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-67577

Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-67578

Missing Authorization vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Exploiting Incorrectly Configured Access Control Security …

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-67579

Missing Authorization vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-67580

Missing Authorization vulnerability in Constant Contact Constant Contact + WooCommerce constant-contact-woocommerce allows Exploiting Incorrectly Con…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-67581

Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Contr…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-67582

Missing Authorization vulnerability in wbcomdesigns Wbcom Designs lock-my-bp allows Exploiting Incorrectly Configured Access Control Security Levels.…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-67571

Missing Authorization vulnerability in WPFunnels WPFunnels wpfunnels allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-67572

Missing Authorization vulnerability in PenciDesign PenNews pennews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

Mitigation only
Fix from $1,600 2025-12-09