Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified CRITICAL 9.8
CVE-2025-13342

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to…

Mitigation only
Fix from $2,300 2025-12-03
Unclassified MEDIUM 5.4
CVE-2025-12887

The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not p…

Mitigation only
Fix from $1,600 2025-12-03
Unclassified MEDIUM 5.3
CVE-2025-13472

A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like cre…

Mitigation only
Fix from $1,600 2025-12-03
Unclassified MEDIUM 5.3
CVE-2025-10304

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a m…

Mitigation only
Fix from $1,600 2025-12-03
Unclassified CRITICAL 9.0
CVE-2025-13828

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settin…

Mitigation only
Fix from $2,300 2025-12-02
Gim MEDIUM 5.3
CVE-2025-41012

Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a use…

Fix: 2025-04-01+
Fix from $1,600 2025-12-02
Mogublog HIGH 8.1
CVE-2025-13813

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the componen…

Fix: after 5.2
Fix from $1,950 2025-12-01
Scada Lts HIGH 8.8
CVE-2025-13790

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The…

Fix: after 2.7.8.1
Fix from $1,950 2025-11-30
Pubnet CRITICAL 9.8
CVE-2025-65112

PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated use…

Fix: 1.1.4+
Fix from $2,300 2025-11-29
Unclassified MEDIUM 5.3
CVE-2025-13381

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check …

Mitigation only
Fix from $1,600 2025-11-27
Unclassified MEDIUM 5.3
CVE-2025-13441

The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.…

Mitigation only
Fix from $1,600 2025-11-27
Unclassified MEDIUM 5.3
CVE-2025-12579

The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'logoff' action i…

Mitigation only
Fix from $1,600 2025-11-27
Classroomio CRITICAL 9.1
CVE-2025-65669

An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authent…

No fix yet
Fix from $2,300 2025-11-26
Youlai Boot HIGH 7.5
CVE-2025-55471

Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.

No fix yet
Fix from $1,950 2025-11-26
Ruoyi HIGH 7.5
CVE-2025-46175

Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserContr…

Mitigation only
Fix from $1,950 2025-11-26
Ruoyi HIGH 7.5
CVE-2025-46174

Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserControll…

Mitigation only
Fix from $1,950 2025-11-26
Unclassified HIGH 8.6
CVE-2025-12061

The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users…

Mitigation only
Fix from $1,950 2025-11-26
Faction CRITICAL 9.8
CVE-2025-66022

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension fra…

Fix: 1.7.1+
Fix from $2,300 2025-11-26
Unclassified MEDIUM 5.3
CVE-2025-13404

The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing authorization validation on the dup…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified MEDIUM 5.3
CVE-2025-13405

The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing authorization validation on the …

Mitigation only
Fix from $1,600 2025-11-25
Unclassified MEDIUM 5.3
CVE-2025-13414

The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing capability check on the cdas…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified MEDIUM 5.3
CVE-2025-13386

The Social Images Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'options_up…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified MEDIUM 5.3
CVE-2025-12043

The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Mitigation only
Fix from $1,600 2025-11-25
MongoDB MEDIUM 6.5
CVE-2025-13643

A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. Th…

Fix: 7.0.26 / 8.0.14+
Fix from $1,600 2025-11-25
Unclassified MEDIUM 5.4
CVE-2025-13558

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified HIGH 8.7
CVE-2025-41016

Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm …

Mitigation only
Fix from $1,950 2025-11-24
Unclassified MEDIUM 6.9
CVE-2025-41017

Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve perspective parameters from secur…

Mitigation only
Fix from $1,600 2025-11-24
Unclassified MEDIUM 5.3
CVE-2025-13318

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is d…

Mitigation only
Fix from $1,600 2025-11-22
Idonate MEDIUM 5.3
CVE-2025-12877

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a mi…

Fix: 2.1.16+
Fix from $1,600 2025-11-22
Unclassified MEDIUM 5.3
CVE-2025-13317

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is du…

Mitigation only
Fix from $1,600 2025-11-22