Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2025-49234 Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Ac… Mitigation only Fix from $1,6002025-06-17 HIGH 8.8 CVE-2025-6105 A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.ja… Jfinal Cms No fix yet Fix from $1,9502025-06-16 MEDIUM 6.5 CVE-2025-48916 Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.… Bookable Calendar 2.2.13+ Fix from $1,6002025-06-13 MEDIUM 5.3 CVE-2025-5815 The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_b… Mitigation only Fix from $1,6002025-06-13 HIGH 7.5 CVE-2025-5282 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing … Wp Travel Engine 6.5.2+ Fix from $1,9502025-06-13 CRITICAL 9.8 CVE-2025-5288 The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a mi… Mitigation only Fix from $2,3002025-06-13 HIGH 8.6 CVE-2025-49181 Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could als… Media Server Mitigation only Fix from $1,9502025-06-12 MEDIUM 5.3 CVE-2025-48444 Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0. Quick Node Block Mitigation only Fix from $1,6002025-06-11 MEDIUM 5.3 CVE-2025-48013 Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0. Quick Node Block Mitigation only Fix from $1,6002025-06-11 HIGH 8.3 CVE-2025-29756 SunGrow's back end users system iSolarCloud https://isolarcloud.com  uses an MQTT service to transport data from the user's connected devices to the… Mitigation only Fix from $1,9502025-06-11 MEDIUM 5.6 CVE-2025-1055 A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL reque… Mitigation only Fix from $1,6002025-06-11 MEDIUM 5.3 CVE-2025-27505 GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the default REST API security and ac… Geoserver 2.25.6 / 2.26.3+ Fix from $1,6002025-06-10 MEDIUM 5.3 CVE-2025-49509 Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Exploiting Incorrectly Configured Access… Mitigation only Fix from $1,6002025-06-10 CRITICAL 9.6 CVE-2025-42989 RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successfu… Mitigation only Fix from $2,3002025-06-10 MEDIUM 6.7 CVE-2025-42993 Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Confi… Mitigation only Fix from $1,6002025-06-10 HIGH 8.8 CVE-2025-42982 SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system creden… Mitigation only Fix from $1,9502025-06-10 HIGH 8.5 CVE-2025-42983 SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss … Mitigation only Fix from $1,9502025-06-10 MEDIUM 5.4 CVE-2025-42984 SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker coul… Mitigation only Fix from $1,6002025-06-10 HIGH 7.1 CVE-2025-5900 A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cro… Ac9 Firmware No fix yet Fix from $1,9502025-06-09 MEDIUM 6.5 CVE-2025-5888 A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionalit… Webstack Guns No fix yet Fix from $1,6002025-06-09 HIGH 8.1 CVE-2025-49651 Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in… Mitigation only Fix from $1,9502025-06-09 HIGH 7.5 CVE-2025-49265 Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Co… Mitigation only Fix from $1,9502025-06-09 MEDIUM 6.5 CVE-2025-48147 Missing Authorization vulnerability in Crypto Cloud CryptoCloud - Crypto Payment Gateway cryptocloud-crypto-payment-gateway allows Exploiting Incorre… Mitigation only Fix from $1,6002025-06-09 MEDIUM 6.5 CVE-2025-48139 Missing Authorization vulnerability in relentlo StyleAI relentlosoftware allows Accessing Functionality Not Properly Constrained by ACLs.This issue a… Mitigation only Fix from $1,6002025-06-09 HIGH 7.1 CVE-2025-47527 Missing Authorization vulnerability in Icegram Icegram Collect icegram-rainmaker allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,9502025-06-09 HIGH 7.1 CVE-2025-47463 Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Co… Mitigation only Fix from $1,9502025-06-09 HIGH 7.6 CVE-2025-32308 Missing Authorization vulnerability in looks_awesome Team Builder a-team-showcase allows Exploiting Incorrectly Configured Access Control Security Le… Mitigation only Fix from $1,9502025-06-09 HIGH 8.8 CVE-2025-5894 Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attackers with regular privileges … Mitigation only Fix from $1,9502025-06-09 HIGH 8.8 CVE-2025-47601 Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a… Mitigation only Fix from $1,9502025-06-07 MEDIUM 5.3 CVE-2025-5814 The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… Mitigation only Fix from $1,6002025-06-07