Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.8 CVE-2025-52954 A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-p… Junos Os Evolved 22.2+ Fix from $1,9502025-07-11 CRITICAL 9.6 CVE-2025-52950 A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with m… Security Director Mitigation only Fix from $2,3002025-07-11 MEDIUM 6.5 CVE-2025-3780 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized m… Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible 6.7.17+ Fix from $1,6002025-07-09 HIGH 8.8 CVE-2025-49723 Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally. Windows 10 1809 10.0.17763.7558 / 10.0.19044.6093+ Fix from $1,9502025-07-08 MEDIUM 5.3 CVE-2025-5957 The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a mi… Mitigation only Fix from $1,6002025-07-08 HIGH 7.7 CVE-2025-42952 SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, poten… Mitigation only Fix from $1,9502025-07-08 HIGH 8.1 CVE-2025-42953 SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. … Mitigation only Fix from $1,9502025-07-08 CRITICAL 9.1 CVE-2025-53495 Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki… Mitigation only Fix from $2,3002025-07-07 CRITICAL 9.1 CVE-2025-53499 Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki… Mitigation only Fix from $2,3002025-07-07 MEDIUM 5.4 CVE-2025-7133 A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manip… Online Movie Ticket Booking System No fix yet Fix from $1,6002025-07-07 HIGH 7.5 CVE-2025-53485 SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related t… Mitigation only Fix from $1,9502025-07-04 HIGH 8.1 CVE-2025-52813 Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mo… Mitigation only Fix from $1,9502025-07-04 MEDIUM 6.5 CVE-2025-50039 Missing Authorization vulnerability in vgwort VG WORT METIS vgw-metis allows Exploiting Incorrectly Configured Access Control Security Levels.This is… Mitigation only Fix from $1,6002025-07-04 MEDIUM 6.5 CVE-2025-50032 Missing Authorization vulnerability in Paytiko - Payment Orchestration Platform Paytiko for WooCommerce paytiko allows Exploiting Incorrectly Configu… Mitigation only Fix from $1,6002025-07-04 MEDIUM 6.5 CVE-2025-49431 Missing Authorization vulnerability in Gnuget MF Plus WPML mf-plus-wpml allows Exploiting Incorrectly Configured Access Control Security Levels.This … Mitigation only Fix from $1,6002025-07-04 MEDIUM 6.5 CVE-2025-47634 Missing Authorization vulnerability in Keylor Mendoza WC Pickup Store wc-pickup-store allows Exploiting Incorrectly Configured Access Control Securit… Mitigation only Fix from $1,6002025-07-04 MEDIUM 6.3 CVE-2025-47565 Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af… Mitigation only Fix from $1,6002025-07-04 MEDIUM 5.3 CVE-2025-30929 Missing Authorization vulnerability in amazewp fluXtore fluxtore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a… Mitigation only Fix from $1,6002025-07-04 MEDIUM 5.3 CVE-2025-29012 Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on CF7-mailchimp-addon allows Exploiting Incorrectly Configured Access Contro… Mitigation only Fix from $1,6002025-07-04 MEDIUM 5.3 CVE-2025-24757 Missing Authorization vulnerability in AndonDesign uDesign udesign.This issue affects uDesign: from n/a through <= 4.11.2. Mitigation only Fix from $1,6002025-07-04 MEDIUM 5.3 CVE-2025-24748 Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10. No fix yet Fix from $1,6002025-07-04 HIGH 7.5 CVE-2025-6814 The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_now() function in ver… Mitigation only Fix from $1,9502025-07-04 HIGH 8.8 CVE-2025-5953 The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee(… Wp Human Resource Management after 2.2.17 Fix from $1,9502025-07-04 HIGH 8.1 CVE-2025-5956 The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_… Wp Human Resource Management after 2.2.17 Fix from $1,9502025-07-04 MEDIUM 5.4 CVE-2025-3702 Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting Incorrectly Configured Access … Melapress File Monitor 2.2.0+ Fix from $1,6002025-07-03 MEDIUM 6.8 CVE-2025-27461 During startup, the device automatically logs in the EPC2 Windows user without requesting a password. Meac300 Fnade4 Firmware Mitigation only Fix from $1,6002025-07-03 MEDIUM 5.3 CVE-2025-53108 HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in the API endpoints responsible… Patch available Fix from $1,6002025-07-02 MEDIUM 6.5 CVE-2025-39362 Missing Authorization vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce.This issue affects Mollie Payments for … Mitigation only Fix from $1,6002025-07-02 MEDIUM 5.4 CVE-2025-46259 Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control … Mitigation only Fix from $1,6002025-07-01 CRITICAL 9.8 CVE-2025-5304 The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() func… Pt Project Notebooks after 1.1.3 Fix from $2,3002025-06-28