Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.5
CVE-2025-57955

Missing Authorization vulnerability in Plugin Devs Post Carousel Slider for Elementor post-carousel-slider-for-elementor allows Exploiting Incorrectl…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.3
CVE-2025-57957

Missing Authorization vulnerability in wpcraft WooMS wooms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.4
CVE-2025-57949

Missing Authorization vulnerability in oggix Ongkoskirim.id ongkoskirim-id allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.3
CVE-2025-57944

Missing Authorization vulnerability in Skimlinks Skimlinks Affiliate Marketing Tool skimlinks allows Accessing Functionality Not Properly Constrained…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.3
CVE-2025-57939

Missing Authorization vulnerability in Blocksera Image Hover Effects – Elementor Addon image-hover-effects-addon-for-elementor allows Exploiting Inco…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.3
CVE-2025-57921

Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Contro…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.3
CVE-2025-57907

Missing Authorization vulnerability in Heureka Group Heureka heureka allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 6.5
CVE-2025-57909

Missing Authorization vulnerability in Rouergue Création Editor Custom Color Palette editor-custom-color-palette allows Exploiting Incorrectly Config…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.3
CVE-2025-57899

Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Accessing Functionality Not Properly Constrained by ACLs…

Mitigation only
Fix from $1,600 2025-09-22
Cubecart MEDIUM 6.5
CVE-2025-59413

CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attac…

Fix: 6.5.11+
Fix from $1,600 2025-09-22
Unclassified HIGH 8.8
CVE-2025-57605

Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges b…

Mitigation only
Fix from $1,950 2025-09-22
Unclassified MEDIUM 5.3
CVE-2025-10305

The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_passkey() and passkeys_…

Mitigation only
Fix from $1,600 2025-09-20
Unclassified HIGH 8.1
CVE-2025-7665

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'ha…

Mitigation only
Fix from $1,950 2025-09-19
Unclassified MEDIUM 5.4
CVE-2025-8487

The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the kubio-image…

Mitigation only
Fix from $1,600 2025-09-19
Unclassified CRITICAL 9.8
CVE-2025-10690

The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability che…

Mitigation only
Fix from $2,300 2025-09-19
Unclassified HIGH 8.1
CVE-2025-8565

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized acces…

Mitigation only
Fix from $1,950 2025-09-18
Dragonfly HIGH 7.5
CVE-2025-59353

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for …

Fix: 2.1.0+
Fix from $1,950 2025-09-17
Unclassified HIGH 7.2
CVE-2025-59416

The Scratch Channel is a news website. If the user makes a fork, they can change the admins and make an article. Since the API uses a POST request, i…

Mitigation only
Fix from $1,950 2025-09-17
Jenkins MEDIUM 5.3
CVE-2025-59474

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users l…

Fix: 2.516.3 / 2.528+
Fix from $1,600 2025-09-17
Unclassified MEDIUM 5.3
CVE-2025-8999

The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_modules' functio…

Mitigation only
Fix from $1,600 2025-09-17
Digital Experience Platform MEDIUM 5.3
CVE-2025-43805

Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 3…

Fix: 7.4.3.112 / 2023.Q3.5+
Fix from $1,600 2025-09-16
Ipados HIGH 8.8
CVE-2025-43358

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS …

Fix: 14.8 / 15.7+
Fix from $1,950 2025-09-15
macOS HIGH 7.8
CVE-2025-43341

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to gain …

Fix: 14.8 / 26.0+
Fix from $1,950 2025-09-15
Ipados HIGH 8.8
CVE-2025-43329

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, watchOS 26. An …

Fix: 26.0+
Fix from $1,950 2025-09-15
macOS MEDIUM 5.1
CVE-2025-43311

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may…

Fix: 14.8 / 15.7+
Fix from $1,600 2025-09-15
macOS HIGH 7.8
CVE-2025-43316

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26, visionOS 26. A malicious app may be able to ga…

Fix: 26.0+
Fix from $1,950 2025-09-15
macOS MEDIUM 6.2
CVE-2025-43318

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Tahoe 26. An app with root privileges may be able to access…

Fix: 26.0+
Fix from $1,600 2025-09-15
macOS HIGH 7.8
CVE-2025-43286

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app …

Fix: 14.8 / 15.7+
Fix from $1,950 2025-09-15
Mattermost Server MEDIUM 6.5
CVE-2025-9076

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious o…

Fix: 10.10.2+
Fix from $1,600 2025-09-15
Unclassified HIGH 8.8
CVE-2025-9018

The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'tt_update…

Mitigation only
Fix from $1,950 2025-09-11