Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Rallly CRITICAL 9.1
CVE-2025-65021

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists i…

Fix: 4.5.4+
Fix from $2,300 2025-11-19
Unclassified MEDIUM 6.5
CVE-2025-12174

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a…

Mitigation only
Fix from $1,600 2025-11-19
Unclassified HIGH 7.5
CVE-2025-12955

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39.…

Mitigation only
Fix from $1,950 2025-11-18
Unclassified MEDIUM 5.3
CVE-2025-12391

The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hand…

Mitigation only
Fix from $1,600 2025-11-18
Unclassified MEDIUM 5.3
CVE-2025-12392

The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit…

Mitigation only
Fix from $1,600 2025-11-18
Unclassified MEDIUM 5.4
CVE-2025-11734

The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to unauthorized post modificati…

Mitigation only
Fix from $1,600 2025-11-18
Unclassified MEDIUM 6.5
CVE-2025-12937

The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ac…

Mitigation only
Fix from $1,600 2025-11-18
Unclassified HIGH 7.2
CVE-2025-11620

The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mrpu_ad…

Mitigation only
Fix from $1,950 2025-11-18
Unclassified MEDIUM 5.3
CVE-2025-12849

The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugi…

Mitigation only
Fix from $1,600 2025-11-15
Wholesale MEDIUM 6.5
CVE-2025-13179

A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects so…

Fix: after 2025-10-16
Fix from $1,600 2025-11-14
Saleserp HIGH 8.8
CVE-2025-13177

A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site reque…

Fix: after 2025-10-16
Fix from $1,950 2025-11-14
Simple E Banking System MEDIUM 6.5
CVE-2025-13119

A flaw has been found in Fabian Ros/SourceCodester Simple E-Banking System 1.0. This affects an unknown part. This manipulation causes cross-site req…

No fix yet
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-64384

Missing Authorization vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-64277

Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 6.5
CVE-2025-64369

Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Se…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-64370

Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 6.5
CVE-2025-64276

Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-64259

Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security L…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.4
CVE-2025-64261

Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Exploiting Incorrectly Configured …

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.4
CVE-2025-64263

Missing Authorization vulnerability in PluginEver WP Content Pilot wp-content-pilot allows Exploiting Incorrectly Configured Access Control Security …

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-12891

The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results'…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-12892

The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_o…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-12979

The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' acti…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified HIGH 7.3
CVE-2025-13063

A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. Th…

Mitigation only
Fix from $1,950 2025-11-12
Openoffice MEDIUM 5.3
CVE-2025-64407

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,600 2025-11-12
Openoffice MEDIUM 6.5
CVE-2025-64402

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,600 2025-11-12
Openoffice HIGH 8.1
CVE-2025-64403

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64404

Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64405

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64401

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,950 2025-11-12