Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Ide Services HIGH 8.8
CVE-2025-58334

In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves

Fix: 2025.4.2.2164 / 2025.5.0.1086+
Fix from $1,950 2025-08-28
Unclassified MEDIUM 5.8
CVE-2025-54734

Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

Mitigation only
Fix from $1,600 2025-08-28
Unclassified MEDIUM 6.5
CVE-2025-54733

Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting Incorrectly Configured Access…

Mitigation only
Fix from $1,600 2025-08-28
Unclassified HIGH 7.1
CVE-2025-54714

Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Cont…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 7.1
CVE-2025-54710

Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality Not Properly Constrained by ACLs.This issue …

Mitigation only
Fix from $1,950 2025-08-28
Unclassified MEDIUM 5.4
CVE-2025-53337

Missing Authorization vulnerability in Ashan Perera LifePress lifepress allows Exploiting Incorrectly Configured Access Control Security Levels.This …

No fix yet
Fix from $1,600 2025-08-28
Unclassified HIGH 7.6
CVE-2025-53230

Missing Authorization vulnerability in honzat Page Manager for Elementor page-manager-for-elementor allows Exploiting Incorrectly Configured Access C…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified MEDIUM 5.3
CVE-2025-48327

Missing Authorization vulnerability in inkthemes WP Mailgun SMTP wp-mailgun-smtp allows Accessing Functionality Not Properly Constrained by ACLs.This…

Mitigation only
Fix from $1,600 2025-08-28
Unclassified MEDIUM 5.3
CVE-2025-7956

The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in its AJAX search handler in all …

Mitigation only
Fix from $1,600 2025-08-28
GitLab MEDIUM 5.3
CVE-2025-2246

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed…

Fix: 18.1.5 / 18.2.5+
Fix from $1,600 2025-08-27
Unclassified MEDIUM 6.5
CVE-2025-58198

Missing Authorization vulnerability in Xpro Xpro Theme Builder xpro-theme-builder allows Exploiting Incorrectly Configured Access Control Security Le…

Mitigation only
Fix from $1,600 2025-08-27
Unclassified MEDIUM 5.3
CVE-2025-58201

Missing Authorization vulnerability in AfterShip & Automizely AfterShip Tracking aftership-woocommerce-tracking allows Accessing Functionality Not Pr…

Mitigation only
Fix from $1,600 2025-08-27
Wp Bulk Delete MEDIUM 5.4
CVE-2025-58192

Missing Authorization vulnerability in Xylus Themes WP Bulk Delete wp-bulk-delete allows Exploiting Incorrectly Configured Access Control Security Le…

Fix: 1.3.7+
Fix from $1,600 2025-08-27
Android MEDIUM 6.2
CVE-2025-0086

In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to loca…

Mitigation only
Fix from $1,600 2025-08-26
Unclassified MEDIUM 6.5
CVE-2025-48108

Missing Authorization vulnerability in Mojoomla School Management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

Mitigation only
Fix from $1,600 2025-08-26
Unclassified MEDIUM 5.3
CVE-2025-7821

The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pluswc_logo_favicon_log…

Mitigation only
Fix from $1,600 2025-08-23
Unopim HIGH 8.1
CVE-2025-55741

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the…

Fix: 0.3.1+
Fix from $1,950 2025-08-22
Unclassified MEDIUM 5.3
CVE-2025-57896

Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.T…

Mitigation only
Fix from $1,600 2025-08-22
Unclassified CRITICAL 9.8
CVE-2025-52352

Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign…

Mitigation only
Fix from $2,300 2025-08-21
Unclassified MEDIUM 6.5
CVE-2025-54040

Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Incorrectly Configured Access Con…

Mitigation only
Fix from $1,600 2025-08-20
Unclassified MEDIUM 6.5
CVE-2025-54025

Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Exploiting Incorrectly Configured Access Co…

Mitigation only
Fix from $1,600 2025-08-20
Unclassified HIGH 8.5
CVE-2025-49406

Missing Authorization vulnerability in favethemes Houzez allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Houzez: …

Mitigation only
Fix from $1,950 2025-08-20
Flaskblog MEDIUM 6.5
CVE-2025-55734

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but no…

Fix: after 2.8.0
Fix from $1,600 2025-08-19
Unclassified HIGH 8.5
CVE-2025-4046

A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization

Mitigation only
Fix from $1,950 2025-08-19
Unclassified MEDIUM 5.3
CVE-2025-7499

The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers…

Mitigation only
Fix from $1,600 2025-08-16
Unclassified CRITICAL 9.8
CVE-2025-8898

The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up t…

Mitigation only
Fix from $2,300 2025-08-16
Unclassified HIGH 7.5
CVE-2025-7664

The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the check_activate_permission() permission…

Mitigation only
Fix from $1,950 2025-08-16
Config Pages HIGH 7.6
CVE-2025-8361

Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: from 0.0.0 before 2.18.0.

Fix: 2.18.0+
Fix from $1,950 2025-08-15
Unclassified MEDIUM 5.3
CVE-2025-49432

Missing Authorization vulnerability in FWDesign Ultimate Video Player fwduvp allows Exploiting Incorrectly Configured Access Control Security Levels.…

Mitigation only
Fix from $1,600 2025-08-15
Unclassified HIGH 8.1
CVE-2025-8342

The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty v…

Mitigation only
Fix from $1,950 2025-08-15