Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-12891

The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results'…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-12892

The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_o…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-12979

The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' acti…

Mitigation only
Fix from $1,600 2025-11-13
Unclassified HIGH 7.3
CVE-2025-13063

A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. Th…

Mitigation only
Fix from $1,950 2025-11-12
Openoffice MEDIUM 5.3
CVE-2025-64407

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,600 2025-11-12
Openoffice MEDIUM 6.5
CVE-2025-64402

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,600 2025-11-12
Openoffice HIGH 8.1
CVE-2025-64403

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64404

Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64405

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64401

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Unclassified HIGH 7.5
CVE-2025-12633

The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili…

Mitigation only
Fix from $1,950 2025-11-12
Nuance Powerscribe 360 HIGH 8.1
CVE-2025-30398

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2025-11-11
Unclassified MEDIUM 5.3
CVE-2025-33185

NVIDIA AIStore contains a vulnerability in AuthN where an unauthenticated user may cause information disclosure.  A successful exploit of this vulner…

Mitigation only
Fix from $1,600 2025-11-11
Endpoint Security MEDIUM 5.5
CVE-2025-5317

An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with admini…

Fix: 7.20.52.200087+
Fix from $1,600 2025-11-11
Find Unused Images MEDIUM 5.3
CVE-2025-11996

The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() an…

Fix: after 1.0.7
Fix from $1,600 2025-11-11
Unclassified MEDIUM 5.3
CVE-2025-11999

The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultip…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 5.3
CVE-2025-11894

The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpo…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 5.3
CVE-2025-11988

The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plu…

Mitigation only
Fix from $1,600 2025-11-11
Youtrack HIGH 7.5
CVE-2025-64684

In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

Fix: 2025.3.104432+
Fix from $1,950 2025-11-10
Forest MEDIUM 6.5
CVE-2025-12924

A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the fi…

Fix: after 2025-09-07
Fix from $1,600 2025-11-10
Forest CRITICAL 9.8
CVE-2025-12925

A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/…

Fix: after 2025-09-04
Fix from $2,300 2025-11-10
Unclassified MEDIUM 6.5
CVE-2025-7663

The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /…

Mitigation only
Fix from $1,600 2025-11-08
Unclassified MEDIUM 5.3
CVE-2025-12042

The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in the csv-export.php f…

Mitigation only
Fix from $1,600 2025-11-08
Unclassified MEDIUM 6.4
CVE-2025-12583

The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_n…

Mitigation only
Fix from $1,600 2025-11-08
Idonate MEDIUM 6.5
CVE-2025-4522

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admi…

Fix: 2.1.10+
Fix from $1,600 2025-11-07
Unclassified MEDIUM 5.3
CVE-2025-64323

kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any c…

Patch available
Fix from $1,600 2025-11-07
Unclassified HIGH 8.1
CVE-2025-5483

The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wizard/inc/wp_user.php file in …

Mitigation only
Fix from $1,950 2025-11-07
Unclassified MEDIUM 5.3
CVE-2025-64179

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below, missing authentication in th…

Patch available
Fix from $1,600 2025-11-06
Unclassified MEDIUM 6.5
CVE-2025-62914

Missing Authorization vulnerability in anibalwainstein Effect Maker effect-maker allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2025-11-06
Unclassified MEDIUM 6.5
CVE-2025-62046

Missing Authorization vulnerability in CodexThemes TheGem Demo Import (for WPBakery) thegem-importer.This issue affects TheGem Demo Import (for WPBak…

Mitigation only
Fix from $1,600 2025-11-06