Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 8.2
CVE-2025-7040

The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization…

Mitigation only
Fix from $1,950 2025-09-06
Unclassified MEDIUM 6.5
CVE-2025-53571

Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control …

Mitigation only
Fix from $1,600 2025-09-05
Unclassified MEDIUM 6.5
CVE-2025-54744

Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured A…

No fix yet
Fix from $1,600 2025-09-05
Android MEDIUM 5.5
CVE-2024-0028

In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permission check. This could lead to l…

Mitigation only
Fix from $1,600 2025-09-05
Unclassified MEDIUM 5.4
CVE-2025-58785

Missing Authorization vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows Exploiting Incorrectly Configured Access …

Mitigation only
Fix from $1,600 2025-09-05
Android HIGH 7.8
CVE-2025-22414

In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permission check. This could lead to…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.3
CVE-2025-48547

In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead to local escalation of privil…

No fix yet
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-48549

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escal…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-48524

In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of …

Mitigation only
Fix from $1,600 2025-09-04
Android MEDIUM 5.5
CVE-2025-26445

In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local i…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.8
CVE-2025-26450

In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motion events to the default IME d…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-26440

In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lea…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-26437

In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permissi…

Patch available
Fix from $1,600 2025-09-04
Unclassified MEDIUM 6.5
CVE-2025-8268

The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delet…

Mitigation only
Fix from $1,600 2025-09-03
Unclassified MEDIUM 5.4
CVE-2025-58639

Missing Authorization vulnerability in Ali Khallad Contact Form By Mega Forms mega-forms allows Exploiting Incorrectly Configured Access Control Secu…

Mitigation only
Fix from $1,600 2025-09-03
Unclassified MEDIUM 5.3
CVE-2025-58634

Missing Authorization vulnerability in peachpay PeachPay Payments peachpay-for-woocommerce allows Exploiting Incorrectly Configured Access Control Se…

Mitigation only
Fix from $1,600 2025-09-03
Unclassified MEDIUM 5.3
CVE-2025-58635

Missing Authorization vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2025-09-03
Unclassified MEDIUM 6.5
CVE-2025-58616

Missing Authorization vulnerability in Frisbii Frisbii Pay reepay-checkout-gateway allows Exploiting Incorrectly Configured Access Control Security L…

No fix yet
Fix from $1,600 2025-09-03
Unclassified MEDIUM 5.3
CVE-2025-58613

Missing Authorization vulnerability in Barn2 Plugins Posts Table with Search & Sort posts-data-table allows Exploiting Incorrectly Configured Access …

Mitigation only
Fix from $1,600 2025-09-03
Unclassified MEDIUM 5.0
CVE-2025-58606

Missing Authorization vulnerability in cozythemes SaasLauncher saaslauncher allows Exploiting Incorrectly Configured Access Control Security Levels.T…

Mitigation only
Fix from $1,600 2025-09-03
Unclassified MEDIUM 5.3
CVE-2025-58600

Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access…

Mitigation only
Fix from $1,600 2025-09-03
Unclassified MEDIUM 5.3
CVE-2025-58603

Missing Authorization vulnerability in Surfer Surfer surferseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

No fix yet
Fix from $1,600 2025-09-03
Makeaholic CRITICAL 9.8
CVE-2025-58210

Missing Authorization vulnerability in ThemeMove Makeaholic makeaholic allows Exploiting Incorrectly Configured Access Control Security Levels.This i…

Fix: 1.8.7+
Fix from $2,300 2025-09-03
Android HIGH 7.3
CVE-2025-22439

In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission c…

Mitigation only
Fix from $1,950 2025-09-02
Eco Dc HIGH 8.8
CVE-2025-6685

ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected i…

Fix: 1.2.116+
Fix from $1,950 2025-09-02
Koillection HIGH 8.8
CVE-2025-9747

A vulnerability has been found in Koillection up to 1.6.18. Affected is an unknown function of the file assets/controllers/csrf_protection_controller…

Fix: 1.7.0+
Fix from $1,950 2025-08-31
Unclassified CRITICAL 9.8
CVE-2024-32832

Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from …

Mitigation only
Fix from $2,300 2025-08-31
Unclassified HIGH 7.1
CVE-2024-32589

Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-m…

Mitigation only
Fix from $1,950 2025-08-31
Ehrd Ctms CRITICAL 9.8
CVE-2025-54943

A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized app…

Fix: 10.11+
Fix from $2,300 2025-08-30
Digital Experience Platform CRITICAL 9.1
CVE-2025-43773

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024…

Fix: 2024.Q1.19 / 2025.Q1.15+
Fix from $2,300 2025-08-29