Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Confluence MEDIUM 6.4
CVE-2025-48731

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscripti…

Fix: 1.5.0+
Fix from $1,600 2025-08-11
Tianti HIGH 8.8
CVE-2025-8807

A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tia…

Fix: after 2.3
Fix from $1,950 2025-08-10
Litmus MEDIUM 5.4
CVE-2025-8796

A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file …

Fix: after 3.19.0
Fix from $1,600 2025-08-10
Gatling MEDIUM 5.3
CVE-2025-51308

In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only end…

Fix: 1.25.0+
Fix from $1,600 2025-08-06
Unclassified HIGH 7.8
CVE-2025-41698

A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.

No fix yet
Fix from $1,950 2025-08-05
Delmia Apriso CRITICAL 9.1
CVE-2025-6205 KEVEPSS 71%

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged acces…

Fix: 2025+
Fix from $2,300 2025-08-04
Unclassified HIGH 8.8
CVE-2025-6754

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect…

Mitigation only
Fix from $1,950 2025-08-02
Unclassified MEDIUM 5.3
CVE-2025-8152

The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missi…

Mitigation only
Fix from $1,600 2025-08-02
Online Movie Streaming HIGH 7.3
CVE-2025-8435

A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by this vulnerability is an unknown…

No fix yet
Fix from $1,950 2025-08-01
Online Movie Streaming HIGH 7.3
CVE-2025-8434

A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is an unknown function of the fil…

No fix yet
Fix from $1,950 2025-08-01
Glpi MEDIUM 6.5
CVE-2025-53111

GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized acc…

Fix: 10.0.19+
Fix from $1,600 2025-07-30
Unclassified CRITICAL 9.8
CVE-2025-46811EPSS 10%

A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any …

Mitigation only
Fix from $2,300 2025-07-30
Unclassified HIGH 8.8
CVE-2025-8322

The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator function…

Mitigation only
Fix from $1,950 2025-07-30
Unclassified HIGH 8.8
CVE-2025-7689

The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() …

Mitigation only
Fix from $1,950 2025-07-29
Brizy MEDIUM 5.3
CVE-2025-4370

The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls funct…

Fix: 2.6.21+
Fix from $1,600 2025-07-29
Haxcms Nodejs HIGH 8.3
CVE-2025-54378

HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 …

Fix: 11.0.9 / 11.0.14+
Fix from $1,950 2025-07-26
Unclassified HIGH 7.5
CVE-2023-7306

The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete…

Mitigation only
Fix from $1,950 2025-07-25
Droip HIGH 8.8
CVE-2025-5835

The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis…

Fix: after 2.2.0
Fix from $1,950 2025-07-25
Platform Theme CRITICAL 9.8
CVE-2015-10143

The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability…

Fix: 1.4.4+
Fix from $2,300 2025-07-25
Unclassified HIGH 8.8
CVE-2025-7695

The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_li…

Mitigation only
Fix from $1,950 2025-07-24
Unclassified CRITICAL 9.8
CVE-2025-6441

The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable t…

Mitigation only
Fix from $2,300 2025-07-24
Unclassified CRITICAL 9.8
CVE-2025-6380

The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in v…

Mitigation only
Fix from $2,300 2025-07-24
Unclassified MEDIUM 5.3
CVE-2025-6215

The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/regist…

Mitigation only
Fix from $1,600 2025-07-23
Unclassified HIGH 8.8
CVE-2025-6190

The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the rp_user_profile() AJAX h…

Mitigation only
Fix from $1,950 2025-07-23
Ajax Load More HIGH 8.8
CVE-2015-10140

The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscribe…

Fix: 2.8.1.2+
Fix from $1,950 2025-07-22
Unclassified CRITICAL 9.8
CVE-2025-6187

The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_info REST endpoint in versions 1…

Mitigation only
Fix from $2,300 2025-07-22
File Download HIGH 7.5
CVE-2025-7717

Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: from 0.0.0 before 1.9.0, from …

Fix: 8.x-1.9+
Fix from $1,950 2025-07-21
Headwind Mdm MEDIUM 6.5
CVE-2025-43720

Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user ro…

Fix: 5.33.1+
Fix from $1,600 2025-07-21
2ndline MEDIUM 5.5
CVE-2025-43976

The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone ca…

No fix yet
Fix from $1,600 2025-07-21
Com.skt.prod.dialer MEDIUM 5.5
CVE-2025-43977

The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without u…

Mitigation only
Fix from $1,600 2025-07-21