Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.4 CVE-2025-48335 Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Exploiting Incorrectly Configured Access Control Securit… Mitigation only Fix from $1,6002025-06-06 HIGH 7.5 CVE-2025-48784 A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to mod… Hr Portal after 7.3.2025.0408 Fix from $1,9502025-06-06 HIGH 8.8 CVE-2025-5732 A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part. … Traffic Offense Reporting System No fix yet Fix from $1,9502025-06-06 CRITICAL 9.8 CVE-2025-5486 The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() func… Mitigation only Fix from $2,3002025-06-06 HIGH 7.1 CVE-2025-5018 The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_updat… Mitigation only Fix from $1,9502025-06-06 MEDIUM 6.4 CVE-2025-1777 The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'ux_cb_page_optio… Mitigation only Fix from $1,6002025-06-06 CRITICAL 9.8 CVE-2025-48133 Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Securi… Uncanny Automator 6.5.0+ Fix from $2,3002025-06-05 MEDIUM 5.4 CVE-2025-46258 Missing Authorization vulnerability in BdThemes Element Pack Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a… Mitigation only Fix from $1,6002025-06-05 HIGH 8.8 CVE-2025-5701 The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capa… Mitigation only Fix from $1,9502025-06-05 HIGH 8.8 CVE-2025-5521 A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functi… Wukong Crm No fix yet Fix from $1,9502025-06-03 HIGH 8.8 CVE-2025-48998 DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allow… Dataease 2.10.6+ Fix from $1,9502025-06-03 CRITICAL 10.0 CVE-2025-45854 /server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams. Jehc Bpm after 2.0.1 Fix from $2,3002025-06-03 MEDIUM 6.5 CVE-2025-47585 Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Function… Mitigation only Fix from $1,6002025-06-02 MEDIUM 6.5 CVE-2025-4597 The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… Mitigation only Fix from $1,6002025-05-30 HIGH 8.0 CVE-2025-46823 openmrs-module-fhir2 provides the FHIR REST API and related services for OpenMRS, an open medical records system. In versions of the FHIR2 module pri… Mitigation only Fix from $1,9502025-05-29 MEDIUM 5.3 CVE-2025-40673 A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessin… Mitigation only Fix from $1,6002025-05-28 HIGH 8.8 CVE-2025-5117 The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_rol… Mitigation only Fix from $1,9502025-05-27 CRITICAL 9.3 CVE-2025-2407 Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vuln… Mitigation only Fix from $2,3002025-05-27 MEDIUM 6.5 CVE-2025-40667 Missing authorization vulnerability in TCMAN's GIM v11. This allows an authenticated attacker to access any functionality of the application even whe… Gim Mitigation only Fix from $1,6002025-05-26 HIGH 8.8 CVE-2025-5132 A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file tmal… Tmall Demo after 2025-05-05 Fix from $1,9502025-05-24 MEDIUM 6.5 CVE-2025-48275 Missing Authorization vulnerability in dastan800 Visual Header visual-header allows Exploiting Incorrectly Configured Access Control Security Levels.… Mitigation only Fix from $1,6002025-05-23 HIGH 8.8 CVE-2025-47690 Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Privilege Escalation.This i… Mitigation only Fix from $1,9502025-05-23 MEDIUM 6.5 CVE-2025-48271 Missing Authorization vulnerability in Leadinfo Leadinfo leadinfo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue … No fix yet Fix from $1,6002025-05-23 MEDIUM 6.5 CVE-2025-47619 Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affects 6Storage Rentals: from n/a… Mitigation only Fix from $1,6002025-05-23 HIGH 7.5 CVE-2025-47558 Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Map… Mitigation only Fix from $1,9502025-05-23 MEDIUM 6.5 CVE-2025-47529 Missing Authorization vulnerability in UX Design Experts Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin experto-cta-widget a… Mitigation only Fix from $1,6002025-05-23 HIGH 7.1 CVE-2025-46488 Missing Authorization vulnerability in dastan800 Visual Builder visual-builder allows Reflected XSS.This issue affects Visual Builder: from n/a throu… Mitigation only Fix from $1,9502025-05-23 HIGH 8.2 CVE-2025-39536 Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Control Security Levels. This i… Mitigation only Fix from $1,9502025-05-23 MEDIUM 5.3 CVE-2025-2506 When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a datab… Mitigation only Fix from $1,6002025-05-22 MEDIUM 5.3 CVE-2025-47942 The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxapp has no built-in protection … Patch available Fix from $1,6002025-05-21