Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-49903

Missing Authorization vulnerability in bdthemes ZoloBlocks zoloblocks allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 5.3
CVE-2025-49906

Missing Authorization vulnerability in StellarWP WPComplete wpcomplete allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified HIGH 8.2
CVE-2025-49910

Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACL…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified MEDIUM 5.3
CVE-2025-49376

Missing Authorization vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 6.3
CVE-2025-49377

Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Access Control Security Levels.T…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 6.5
CVE-2025-48096

Missing Authorization vulnerability in FRESHFACE Custom CSS custom-css-editor allows Exploiting Incorrectly Configured Access Control Security Levels…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified HIGH 7.5
CVE-2025-30944

Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality Not Properly Constrained by A…

Mitigation only
Fix from $1,950 2025-10-22
Financial Services Analytical Applications Infrastructure HIGH 8.1
CVE-2025-61751

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P…

Mitigation only
Fix from $1,950 2025-10-21
Zld HIGH 8.1
CVE-2025-9133EPSS 5%

A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 th…

Fix: 5.41+
Fix from $1,950 2025-10-21
Unclassified MEDIUM 6.5
CVE-2025-11372

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This …

Patch available
Fix from $1,600 2025-10-18
Unclassified MEDIUM 5.4
CVE-2025-11378

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to …

Patch available
Fix from $1,600 2025-10-18
Restaurant Brands International Assistant HIGH 8.6
CVE-2025-62642

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify u…

Fix: after 2025-09-06
Fix from $1,950 2025-10-17
Mattermost Server HIGH 8.1
CVE-2025-58075

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using th…

Fix: 10.5.11 / 10.10.3+
Fix from $1,950 2025-10-16
Mattermost Server HIGH 8.1
CVE-2025-58073

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using th…

Fix: 10.5.11 / 10.10.3+
Fix from $1,950 2025-10-16
Mattermost Server MEDIUM 5.4
CVE-2025-41410

Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allo…

Fix: 10.5.11 / 10.10.3+
Fix from $1,600 2025-10-16
Unclassified HIGH 8.8
CVE-2025-10706

The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'cwp_addons_update_…

Mitigation only
Fix from $1,950 2025-10-16
Unclassified MEDIUM 5.3
CVE-2025-10849

The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_plugin_…

Mitigation only
Fix from $1,600 2025-10-16
Unclassified MEDIUM 5.3
CVE-2025-11692

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the downl…

Mitigation only
Fix from $1,600 2025-10-15
Unclassified MEDIUM 5.3
CVE-2025-11701

The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post statu…

Mitigation only
Fix from $1,600 2025-10-15
Unclassified HIGH 7.2
CVE-2025-10313

The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scripting and Arbitrary Content Repla…

Mitigation only
Fix from $1,950 2025-10-15
Unclassified MEDIUM 5.3
CVE-2025-10648

The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Mitigation only
Fix from $1,600 2025-10-15
Unclassified HIGH 8.8
CVE-2025-10299

The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability che…

Mitigation only
Fix from $1,950 2025-10-15
Unclassified MEDIUM 5.3
CVE-2025-10186

The WhyDonate – FREE Donate button – Crowdfunding – Fundraising plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capa…

Mitigation only
Fix from $1,600 2025-10-15
Unclassified HIGH 7.6
CVE-2025-33182

NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause corruption of the Linux Devi…

Mitigation only
Fix from $1,950 2025-10-14
Unclassified HIGH 8.8
CVE-2025-8593

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is …

Mitigation only
Fix from $1,950 2025-10-11
Unclassified MEDIUM 5.9
CVE-2025-11380

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data du…

Mitigation only
Fix from $1,600 2025-10-11
Facets MEDIUM 6.5
CVE-2025-9549

Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before …

Fix: 2.0.10 / 3.0.1+
Fix from $1,600 2025-10-10
Powerjob HIGH 7.5
CVE-2025-11581

A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the compon…

Fix: after 5.1.2
Fix from $1,950 2025-10-10
Powerjob MEDIUM 5.3
CVE-2025-11580

A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing autho…

Fix: after 5.1.2
Fix from $1,600 2025-10-10
Unclassified MEDIUM 6.1
CVE-2025-8887

Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in …

Mitigation only
Fix from $1,600 2025-10-10