Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.4
CVE-2025-8423

The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtswpt_remove_pl…

Mitigation only
Fix from $1,600 2025-09-11
Unclassified HIGH 8.8
CVE-2025-8425

The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing ca…

Mitigation only
Fix from $1,950 2025-09-11
Unclassified MEDIUM 5.3
CVE-2025-8492

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification …

Mitigation only
Fix from $1,600 2025-09-11
Unclassified MEDIUM 5.8
CVE-2025-36756

A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.

Mitigation only
Fix from $1,600 2025-09-10
Unclassified HIGH 7.7
CVE-2025-10040

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability…

Mitigation only
Fix from $1,950 2025-09-10
Unclassified HIGH 7.8
CVE-2025-49459

Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authenticated user to conduct an escal…

Mitigation only
Fix from $1,950 2025-09-09
Copyparty HIGH 7.5
CVE-2025-58753

Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option…

Fix: 1.19.8+
Fix from $1,950 2025-09-09
Unclassified MEDIUM 5.3
CVE-2025-58980

Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Accessing Functionality Not Prop…

Mitigation only
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.4
CVE-2025-58981

Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly…

No fix yet
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.3
CVE-2025-58978

Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Incorrectly Configured Access Con…

Mitigation only
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.3
CVE-2025-58979

Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

Mitigation only
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.3
CVE-2025-53348

Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

Mitigation only
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.3
CVE-2025-49860

Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.…

No fix yet
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.4
CVE-2025-53291

Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a through <= 2.1.5.

Mitigation only
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.3
CVE-2025-53340

Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awes…

Mitigation only
Fix from $1,600 2025-09-09
Unclassified MEDIUM 6.5
CVE-2025-39541

Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affects WP Simple Booking Calenda…

Mitigation only
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.4
CVE-2025-32688

Missing Authorization vulnerability in Nebojsa Target Video Easy Publish brid-video-easy-publish.This issue affects Target Video Easy Publish: from n…

Mitigation only
Fix from $1,600 2025-09-09
Connect Secure HIGH 7.6
CVE-2025-55148

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723…

Fix: 22.7 / 22.8+
Fix from $1,950 2025-09-09
Neurons For Secure Access MEDIUM 5.4
CVE-2025-8712

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-72…

Fix: 22.7 / 22.8+
Fix from $1,600 2025-09-09
Connect Secure HIGH 8.8
CVE-2025-55142

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723…

Fix: 22.7 / 22.8+
Fix from $1,950 2025-09-09
Connect Secure MEDIUM 5.4
CVE-2025-55144

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723…

Fix: 22.7 / 22.8+
Fix from $1,600 2025-09-09
Neurons For Secure Access HIGH 8.9
CVE-2025-55145

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723…

Fix: 22.7 / 22.8+
Fix from $1,950 2025-09-09
Connect Secure HIGH 8.8
CVE-2025-55141

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723…

Fix: 22.7 / 22.8+
Fix from $1,950 2025-09-09
TYPO3 HIGH 8.8
CVE-2025-59017

Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13…

Fix: 9.5.55 / 10.4.54+
Fix from $1,950 2025-09-09
Unclassified MEDIUM 5.4
CVE-2025-9542

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unautho…

Mitigation only
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.4
CVE-2025-42915

Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functio…

Mitigation only
Fix from $1,600 2025-09-09
Unclassified MEDIUM 6.5
CVE-2025-42917

SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation o…

Mitigation only
Fix from $1,600 2025-09-09
Unclassified MEDIUM 6.5
CVE-2025-42912

SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of priv…

Mitigation only
Fix from $1,600 2025-09-09
Fides HIGH 7.2
CVE-2025-57817

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver …

Fix: 2.69.1+
Fix from $1,950 2025-09-08
Unclassified HIGH 8.4
CVE-2024-36326

Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a standby state, potentially r…

Mitigation only
Fix from $1,950 2025-09-06