Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Canaldenuncia.app HIGH 7.5
CVE-2025-41113

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' informatio…

Fix: 4.4.8+
Fix from $1,950 2025-11-04
Canaldenuncia.app HIGH 7.5
CVE-2025-41114

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' informatio…

Fix: 4.4.8+
Fix from $1,950 2025-11-04
Canaldenuncia.app HIGH 7.5
CVE-2025-41111

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' informatio…

Fix: 4.4.8+
Fix from $1,950 2025-11-04
Canaldenuncia.app HIGH 7.5
CVE-2025-41112

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' informatio…

Fix: 4.4.8+
Fix from $1,950 2025-11-04
Unclassified MEDIUM 5.3
CVE-2025-12350

The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admi…

Mitigation only
Fix from $1,600 2025-11-04
Unclassified CRITICAL 9.8
CVE-2025-12158

The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabilit…

Mitigation only
Fix from $2,300 2025-11-04
Unclassified MEDIUM 5.3
CVE-2025-12157

The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_aja…

Mitigation only
Fix from $1,600 2025-11-04
Unclassified HIGH 7.5
CVE-2025-11890

The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 1.0…

Mitigation only
Fix from $1,950 2025-11-04
Unclassified MEDIUM 6.5
CVE-2025-11758

The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization check in all versions up to, …

Mitigation only
Fix from $1,600 2025-11-04
Unclassified HIGH 8.8
CVE-2025-10896

Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of File with Dangerous Type via…

Mitigation only
Fix from $1,950 2025-11-04
Rise Ultimate Project Manager MEDIUM 6.5
CVE-2025-63293

FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload…

No fix yet
Fix from $1,600 2025-11-03
Unclassified MEDIUM 5.3
CVE-2025-64294

Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue …

Mitigation only
Fix from $1,600 2025-11-03
I HIGH 8.8
CVE-2025-36367

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious acto…

Mitigation only
Fix from $1,950 2025-11-01
Unclassified CRITICAL 9.8
CVE-2025-11833EPSS 51%

The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data …

Mitigation only
Fix from $2,300 2025-11-01
Unclassified MEDIUM 5.3
CVE-2025-11816

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modif…

Mitigation only
Fix from $1,600 2025-11-01
Elog HIGH 7.1
CVE-2025-64348

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifica…

Fix: after 3.1.5-20251014
Fix from $1,950 2025-10-31
Elog HIGH 8.8
CVE-2025-64349

ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset…

Fix: after 3.1.5-20251014
Fix from $1,950 2025-10-31
Unclassified MEDIUM 5.3
CVE-2025-12041

The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'erifl_file' AJAX act…

Mitigation only
Fix from $1,600 2025-10-31
Unclassified MEDIUM 5.3
CVE-2025-11191

The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending o…

Mitigation only
Fix from $1,600 2025-10-31
Nagios Xi CRITICAL 9.8
CVE-2024-13994

Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configu…

Fix: 2024+
Fix from $2,300 2025-10-30
Nagios Xi HIGH 8.8
CVE-2023-7317

Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could a…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi MEDIUM 6.5
CVE-2013-10072

Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly rea…

Fix: after 2011
Fix from $1,600 2025-10-30
Jumpserver HIGH 8.1
CVE-2025-62712

JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4…

Fix: 3.10.20 / 4.10.11+
Fix from $1,950 2025-10-30
Unclassified MEDIUM 5.3
CVE-2025-11881

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mya…

Mitigation only
Fix from $1,600 2025-10-30
Unclassified MEDIUM 5.3
CVE-2025-10008

The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability chec…

Mitigation only
Fix from $1,600 2025-10-30
Dam HIGH 7.5
CVE-2025-9954

Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5.

Fix: 1.1.5+
Fix from $1,950 2025-10-30
Publish To Bitbucket MEDIUM 5.4
CVE-2025-64150

A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to connect to an atta…

Fix: after 0.4
Fix from $1,600 2025-10-29
Mcp Server MEDIUM 5.4
CVE-2025-64132

Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger bui…

Fix: 0.86.v7d3355e6a_a_18+
Fix from $1,600 2025-10-29
Unclassified MEDIUM 5.4
CVE-2025-64285

Missing Authorization vulnerability in Premmerce Premmerce Wholesale Pricing for WooCommerce premmerce-woocommerce-wholesale-pricing allows Exploitin…

Mitigation only
Fix from $1,600 2025-10-29
Unclassified MEDIUM 5.3
CVE-2025-64211

Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows Accessing Functionality Not …

Mitigation only
Fix from $1,600 2025-10-29