Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2025-52954
A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-p…
Junos Os Evolved
22.2+
CRITICAL 9.6
CVE-2025-52950
A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with m…
Security Director
Mitigation only
MEDIUM 6.5
CVE-2025-3780
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized m…
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible
6.7.17+
HIGH 8.8
CVE-2025-49723
Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
Windows 10 1809
10.0.17763.7558 / 10.0.19044.6093+
MEDIUM 5.3
CVE-2025-5957
The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a mi…
Mitigation only
HIGH 7.7
CVE-2025-42952
SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, poten…
Mitigation only
HIGH 8.1
CVE-2025-42953
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. …
Mitigation only
CRITICAL 9.1
CVE-2025-53495
Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki…
Mitigation only
CRITICAL 9.1
CVE-2025-53499
Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki…
Mitigation only
MEDIUM 5.4
CVE-2025-7133
A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manip…
Online Movie Ticket Booking System
No fix yet
HIGH 7.5
CVE-2025-53485
SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related t…
Mitigation only
HIGH 8.1
CVE-2025-52813
Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mo…
Mitigation only
MEDIUM 6.5
CVE-2025-50039
Missing Authorization vulnerability in vgwort VG WORT METIS vgw-metis allows Exploiting Incorrectly Configured Access Control Security Levels.This is…
Mitigation only
MEDIUM 6.5
CVE-2025-50032
Missing Authorization vulnerability in Paytiko - Payment Orchestration Platform Paytiko for WooCommerce paytiko allows Exploiting Incorrectly Configu…
Mitigation only
MEDIUM 6.5
CVE-2025-49431
Missing Authorization vulnerability in Gnuget MF Plus WPML mf-plus-wpml allows Exploiting Incorrectly Configured Access Control Security Levels.This …
Mitigation only
MEDIUM 6.5
CVE-2025-47634
Missing Authorization vulnerability in Keylor Mendoza WC Pickup Store wc-pickup-store allows Exploiting Incorrectly Configured Access Control Securit…
Mitigation only
MEDIUM 6.3
CVE-2025-47565
Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…
Mitigation only
MEDIUM 5.3
CVE-2025-30929
Missing Authorization vulnerability in amazewp fluXtore fluxtore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…
Mitigation only
MEDIUM 5.3
CVE-2025-29012
Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on CF7-mailchimp-addon allows Exploiting Incorrectly Configured Access Contro…
Mitigation only
MEDIUM 5.3
CVE-2025-24757
Missing Authorization vulnerability in AndonDesign uDesign udesign.This issue affects uDesign: from n/a through <= 4.11.2.
Mitigation only
MEDIUM 5.3
CVE-2025-24748
Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.
No fix yet
HIGH 7.5
CVE-2025-6814
The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_now() function in ver…
Mitigation only
HIGH 8.8
CVE-2025-5953
The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee(…
Wp Human Resource Management
after 2.2.17
HIGH 8.1
CVE-2025-5956
The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_…
Wp Human Resource Management
after 2.2.17
MEDIUM 5.4
CVE-2025-3702
Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting Incorrectly Configured Access …
Melapress File Monitor
2.2.0+
MEDIUM 6.8
CVE-2025-27461
During startup, the device automatically logs in the EPC2 Windows user without requesting a password.
Meac300 Fnade4 Firmware
Mitigation only
MEDIUM 5.3
CVE-2025-53108
HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in the API endpoints responsible…
Patch available
MEDIUM 6.5
CVE-2025-39362
Missing Authorization vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce.This issue affects Mollie Payments for …
Mitigation only
MEDIUM 5.4
CVE-2025-46259
Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control …
Mitigation only
CRITICAL 9.8
CVE-2025-5304
The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() func…
Pt Project Notebooks
after 1.1.3