Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Mblog MEDIUM 6.5
CVE-2025-8992

A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site…

Fix: after 3.5.0
Fix from $1,600 2025-08-15
Unclassified MEDIUM 6.5
CVE-2025-55712

Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Exp…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 5.3
CVE-2025-54739

Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Exploiting Incorrectly Configured Access Contro…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 5.3
CVE-2025-54730

Missing Authorization vulnerability in PARETO Digital Embedder for Google Reviews embedder-for-google-reviews allows Accessing Functionality Not Prop…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 5.4
CVE-2025-54717

Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.…

Mitigation only
Fix from $1,600 2025-08-14
Secure Firewall Management Center MEDIUM 6.5
CVE-2025-20301

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to a…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 5.4
CVE-2025-54695

Missing Authorization vulnerability in DevItems HT Mega ht-mega-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified HIGH 7.5
CVE-2025-54692

Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Co…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 7.5
CVE-2025-54679

Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free neon-channel-product-customizer-free allows Exploiting Incorrectly…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 7.3
CVE-2025-52801

Missing Authorization vulnerability in VonStroheim TheBooking thebooking allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 7.1
CVE-2025-52775

Missing Authorization vulnerability in Ronik@UnlimitedWP Project Cost Calculator project-cost-calculator allows Exploiting Incorrectly Configured Acc…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 7.1
CVE-2025-52785

Missing Authorization vulnerability in softnwords SMM API smm-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 7.3
CVE-2025-52800

Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Accessing Functionality Not Properly Con…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified MEDIUM 6.5
CVE-2025-52721

Missing Authorization vulnerability in LCweb Global Gallery allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affec…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified HIGH 7.5
CVE-2025-52731

Missing Authorization vulnerability in themefunction WordPress Event Manager, Event Calendar and Booking Plugin eventin-pro allows Exploiting Incorre…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified MEDIUM 6.5
CVE-2025-50029

Missing Authorization vulnerability in Ashish AI Tools artificial-intelligence-auto-content-generator allows Exploiting Incorrectly Configured Access…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 6.5
CVE-2025-50031

Missing Authorization vulnerability in syedamirhussain91 DB Backup db-backup allows Exploiting Incorrectly Configured Access Control Security Levels.…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified HIGH 7.5
CVE-2025-31425

Missing Authorization vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Exploiting Incorrectly Configured Access Control Secur…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 7.5
CVE-2025-30639

Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified MEDIUM 6.5
CVE-2025-30993

Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Exploiting Incorrect…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 6.5
CVE-2025-28962

Missing Authorization vulnerability in stefanoai Advanced Google Universal Analytics advanced-google-universal-analytics allows Exploiting Incorrectl…

Mitigation only
Fix from $1,600 2025-08-14
Flowise CRITICAL 9.8
CVE-2025-8943EPSS 72%

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inh…

Fix: 3.0.1+
Fix from $2,300 2025-08-14
Windows Server 2022 CRITICAL 9.1
CVE-2025-50171

Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.20348.3989 / 10.0.25398.1791+
Fix from $2,300 2025-08-12
Virtual Application Delivery Controller HIGH 8.8
CVE-2025-8310

Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attack…

Fix: 22.9+
Fix from $1,950 2025-08-12
Unclassified HIGH 8.8
CVE-2025-8418

The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Arbitrary Plugin Installation in all versions up to, and including,…

Mitigation only
Fix from $1,950 2025-08-12
Unclassified MEDIUM 5.3
CVE-2025-47444

Missing Authorization vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Exploiting Incorrectly Configured Access Control Sec…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified HIGH 7.5
CVE-2025-6253

The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inclu…

Mitigation only
Fix from $1,950 2025-08-12
Unclassified CRITICAL 9.8
CVE-2025-8059

The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_re…

Mitigation only
Fix from $2,300 2025-08-12
Confluence MEDIUM 5.3
CVE-2025-8285

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscriptio…

Fix: 1.5.0+
Fix from $1,600 2025-08-11
Confluence MEDIUM 5.0
CVE-2025-54458

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscrip…

Fix: 1.5.0+
Fix from $1,600 2025-08-11