Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-62151

Missing Authorization vulnerability in Virtuaria Virtuaria PagBank / PagSeguro para Woocommerce virtuaria-pagseguro allows Exploiting Incorrectly Con…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-62152

Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Le…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-62153

Missing Authorization vulnerability in Graham Quick Interest Slider quick-interest-slider allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-62085

Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.4
CVE-2025-62086

Missing Authorization vulnerability in akazanstev Яндекс Доставка (Boxberry) boxberry allows Exploiting Incorrectly Configured Access Control Securit…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 6.5
CVE-2025-62090

Missing Authorization vulnerability in Jegstudio Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons gutenverse-news allows Exploit…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-62100

Missing Authorization vulnerability in themerain ThemeRain Core themerain-core allows Exploiting Incorrectly Configured Access Control Security Level…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-49348

Missing Authorization vulnerability in Hype Hype pico allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hype…

No fix yet
Fix from $1,600 2025-12-09
Unclassified MEDIUM 5.5
CVE-2025-42891

Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and export the contents of database…

Mitigation only
Fix from $1,600 2025-12-09
Android MEDIUM 5.5
CVE-2025-48608

In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local in…

Mitigation only
Fix from $1,600 2025-12-08
Android HIGH 7.8
CVE-2025-48599

In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permission check. …

Patch available
Fix from $1,950 2025-12-08
Android MEDIUM 5.5
CVE-2025-48600

In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information…

Mitigation only
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48604

In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local informatio…

Patch available
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48591

In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local informatio…

Mitigation only
Fix from $1,600 2025-12-08
Android HIGH 7.8
CVE-2025-48575

In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass. This could lead to local es…

Patch available
Fix from $1,950 2025-12-08
Android MEDIUM 6.7
CVE-2025-32319

In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. T…

Patch available
Fix from $1,600 2025-12-08
Halo MEDIUM 6.5
CVE-2025-14117

A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The …

No fix yet
Fix from $1,600 2025-12-06
Unclassified MEDIUM 5.3
CVE-2025-13666

The Helloprint plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.2. This is due to the plugin registe…

Mitigation only
Fix from $1,600 2025-12-06
Unclassified MEDIUM 5.3
CVE-2025-13358

The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing authorization checks in vers…

Mitigation only
Fix from $1,600 2025-12-06
Unclassified MEDIUM 5.3
CVE-2025-12721

The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_st…

Mitigation only
Fix from $1,600 2025-12-06
Pro Macros HIGH 8.3
CVE-2025-65036

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Veloc…

Fix: 1.27.1+
Fix from $1,950 2025-12-05
Unclassified MEDIUM 5.3
CVE-2025-13620

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. …

Mitigation only
Fix from $1,600 2025-12-05
Unclassified MEDIUM 5.3
CVE-2025-12876

The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch…

Mitigation only
Fix from $1,600 2025-12-05
Unclassified MEDIUM 5.3
CVE-2025-12355

The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_update_or…

Mitigation only
Fix from $1,600 2025-12-05
Unclassified MEDIUM 5.3
CVE-2025-12093

The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all…

Mitigation only
Fix from $1,600 2025-12-05
Unclassified MEDIUM 5.3
CVE-2025-13528

The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_exp…

Mitigation only
Fix from $1,600 2025-12-05
Unclassified MEDIUM 5.3
CVE-2025-13312

The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_n…

Mitigation only
Fix from $1,600 2025-12-05
Unclassified CRITICAL 9.8
CVE-2025-13313

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is …

Mitigation only
Fix from $2,300 2025-12-05
Beedrive HIGH 7.5
CVE-2025-54159

Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files…

Fix: 1.4.2-13960+
Fix from $1,950 2025-12-04
Mail Server MEDIUM 6.3
CVE-2025-2848

A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical…

Fix: 1.7.6-10676 / 1.7.6-20676+
Fix from $1,600 2025-12-04