Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-6720

The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in…

Mitigation only
Fix from $1,600 2025-07-19
Unclassified MEDIUM 5.3
CVE-2025-6721

The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mrkv_vchasno_kasa_wc_do_m…

Mitigation only
Fix from $1,600 2025-07-19
Azure Machine Learning HIGH 8.8
CVE-2025-49747

Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-07-18
Unclassified MEDIUM 6.5
CVE-2025-7772

The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up t…

Mitigation only
Fix from $1,600 2025-07-18
Unclassified HIGH 8.8
CVE-2025-6718

The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX action in all versions up to…

Mitigation only
Fix from $1,950 2025-07-18
Unclassified MEDIUM 5.3
CVE-2025-5811

The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Mitigation only
Fix from $1,600 2025-07-18
Unclassified HIGH 8.8
CVE-2025-6813

The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() functio…

Mitigation only
Fix from $1,950 2025-07-18
Unclassified MEDIUM 5.3
CVE-2025-3871

Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoA…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified HIGH 7.5
CVE-2025-52803

Missing Authorization vulnerability in uxper Sala allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sala: from n/a …

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.5
CVE-2025-52804

Missing Authorization vulnerability in uxper Nuss nuss allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Nuss: from …

Mitigation only
Fix from $1,950 2025-07-16
Unclassified MEDIUM 6.5
CVE-2025-49884

Missing Authorization vulnerability in alexvtn Internal Linking of Related Contents internal-linking-of-related-contents allows Exploiting Incorrectl…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified HIGH 7.1
CVE-2025-49888

Missing Authorization vulnerability in pimwick PW WooCommerce On Sale! pw-woocommerce-on-sale allows Exploiting Incorrectly Configured Access Control…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified MEDIUM 6.5
CVE-2025-50028

Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifications allows Exploiting Incorrectly Configured Acce…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 6.5
CVE-2025-48339

Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrectly Configured Access Control …

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 6.5
CVE-2025-49319

Missing Authorization vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Exploiting Incorrectly Configured Access C…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 6.5
CVE-2025-30959

Missing Authorization vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocommerce allows Exploiting Incorre…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified HIGH 8.6
CVE-2025-28965

Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Accessing Functionality Not Properly Constrained by ACLs.…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.5
CVE-2025-29000

Missing Authorization vulnerability in August Infotech Multi-language Responsive Contact Form responsive-contact-form allows Accessing Functionality …

Mitigation only
Fix from $1,950 2025-07-16
Unclassified MEDIUM 5.4
CVE-2025-54037

Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Acces…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 5.3
CVE-2025-53986

Missing Authorization vulnerability in themeisle Hestia hestia allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hes…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 5.3
CVE-2025-48166

Missing Authorization vulnerability in sminozzi Stop and Block bots plugin Anti bots antibots allows Accessing Functionality Not Properly Constrained…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 5.4
CVE-2025-48167

Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Exploiting Incorrectly Configured Access Control Security Le…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 5.3
CVE-2025-48155

Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection allows Accessing Functionality N…

Mitigation only
Fix from $1,600 2025-07-16
Ultimate Wp Mail HIGH 8.8
CVE-2025-6993

The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX…

Fix: 1.3.7+
Fix from $1,950 2025-07-16
Unclassified HIGH 8.1
CVE-2025-6043

The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Deletion due to a missing…

Mitigation only
Fix from $1,950 2025-07-16
Conjur MEDIUM 6.5
CVE-2025-49829

Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authentica…

Fix: 1.22.1 / 13.5.1+
Fix from $1,600 2025-07-15
Youtrack HIGH 7.6
CVE-2025-53959

In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible

Fix: 2024.3.85077 / 2025.1.86199+
Fix from $1,950 2025-07-15
Unclassified CRITICAL 9.8
CVE-2025-5394EPSS 49%

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability c…

Mitigation only
Fix from $2,300 2025-07-15
Dokploy CRITICAL 9.8
CVE-2025-53825

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokplo…

Fix: 0.24.3+
Fix from $2,300 2025-07-14
Indico MEDIUM 6.5
CVE-2025-53640

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to…

Fix: 3.3.7+
Fix from $1,600 2025-07-14