Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.7
CVE-2025-8886

Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect A…

Mitigation only
Fix from $1,600 2025-10-10
Space Security Director HIGH 8.6
CVE-2025-59968

A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read …

Fix: 24.1+
Fix from $1,950 2025-10-09
Unclassified CRITICAL 9.3
CVE-2025-10352

Vulnerability in the melis-core module of Melis Technology's Melis Platform, which, if exploited, allows an unauthenticated attacker to create an adm…

Mitigation only
Fix from $2,300 2025-10-08
Opnform MEDIUM 6.3
CVE-2025-11438

A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component A…

Fix: after 1.9.3
Fix from $1,600 2025-10-08
Unclassified HIGH 8.1
CVE-2025-9243

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capability check on the get_cc_or…

Mitigation only
Fix from $1,950 2025-10-04
Givewp MEDIUM 5.3
CVE-2025-11228

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi…

Fix: 4.10.1+
Fix from $1,600 2025-10-04
Unclassified MEDIUM 5.3
CVE-2025-10212

The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple fu…

Mitigation only
Fix from $1,600 2025-10-03
Unclassified CRITICAL 9.1
CVE-2020-36852

The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1,…

Mitigation only
Fix from $2,300 2025-10-01
Pet Grooming Management Software MEDIUM 6.5
CVE-2025-11051

A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code. The manipulation lead…

No fix yet
Fix from $1,600 2025-09-27
Vvveb HIGH 8.8
CVE-2025-11029

A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site …

Fix: after 1.0.7.2
Fix from $1,950 2025-09-26
Unclassified MEDIUM 5.3
CVE-2025-60155

Missing Authorization vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Exploiting Incorrectly Configured Access Control Security …

Mitigation only
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.4
CVE-2025-60127

Missing Authorization vulnerability in ArtistScope CopySafe Web Protection wp-copysafe-web allows Exploiting Incorrectly Configured Access Control Se…

Mitigation only
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.3
CVE-2025-60129

Missing Authorization vulnerability in Yext Yext yext allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Yext: from n…

No fix yet
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.3
CVE-2025-60130

Missing Authorization vulnerability in wedos.com WEDOS Global wgpwpp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec…

Mitigation only
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.3
CVE-2025-60120

Missing Authorization vulnerability in WPDirectoryKit WP Directory Kit wpdirectorykit allows Exploiting Incorrectly Configured Access Control Securit…

Mitigation only
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.3
CVE-2025-60121

Missing Authorization vulnerability in Ex-Themes WooEvents woo-events allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

No fix yet
Fix from $1,600 2025-09-26
Grand Conference HIGH 8.8
CVE-2025-60116

Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Exploiting Incorrectly C…

Fix: 2.6.4+
Fix from $1,950 2025-09-26
Unclassified MEDIUM 6.5
CVE-2025-60098

Missing Authorization vulnerability in Jeff Farthing Theme My Login theme-my-login allows Exploiting Incorrectly Configured Access Control Security L…

Mitigation only
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.4
CVE-2025-60103

Missing Authorization vulnerability in CridioStudio ListingPro listingpro-plugin allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.4
CVE-2025-60096

Missing Authorization vulnerability in CodexThemes TheGem (Elementor) thegem-elementor allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.4
CVE-2025-60097

Missing Authorization vulnerability in CodexThemes TheGem thegem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

No fix yet
Fix from $1,600 2025-09-26
Unclassified HIGH 7.5
CVE-2025-59011

Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified MEDIUM 6.5
CVE-2025-48326

Missing Authorization vulnerability in Acclectic Media Acclectic Media Organizer acclectic-media-organizer allows Exploiting Incorrectly Configured A…

Mitigation only
Fix from $1,600 2025-09-26
Unclassified MEDIUM 5.3
CVE-2025-58919

Missing Authorization vulnerability in guihom Wide Banner wide-banner allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Mitigation only
Fix from $1,600 2025-09-26
GitLab HIGH 7.2
CVE-2025-10871

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintai…

Fix: 18.2.7 / 18.3.3+
Fix from $1,950 2025-09-26
Unclassified MEDIUM 5.3
CVE-2025-9984

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the fifu_ap…

Mitigation only
Fix from $1,600 2025-09-26
Adaptive Security Appliance Software HIGH 8.6
CVE-2025-20362 KEVEPSS 87%

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Softwar…

Fix: 7.0.8.1 / 7.2.10.2+
Fix from $1,950 2025-09-25
Indoor Connect 8855 Firmware HIGH 8.8
CVE-2025-40837

Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher p…

Fix: 2025.q2+
Fix from $1,950 2025-09-25
Flagforge CRITICAL 9.8
CVE-2025-59827

Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any aut…

Mitigation only
Fix from $2,300 2025-09-24
Claude Code CRITICAL 9.8
CVE-2025-59828

Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.0+, Yarn plugins are auto-exe…

Fix: 1.0.39+
Fix from $2,300 2025-09-24