Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2025-4105
The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions in the 'spl…
Mitigation only
HIGH 7.3
CVE-2025-41231
VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be abl…
Cloud Foundation
4.5.2 / 5.2.1.2+
HIGH 8.2
CVE-2025-39350
Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.
Mitigation only
HIGH 8.2
CVE-2025-39352
Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security L…
Grand Restaurant
after 7.0
HIGH 7.5
CVE-2025-39449
Missing Authorization vulnerability in Crocoblock JetWooBuilder jet-woo-builder allows Accessing Functionality Not Properly Constrained by ACLs.This …
Mitigation only
HIGH 7.5
CVE-2025-39451
Missing Authorization vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Accessing Functionality Not Properly Constrained by ACLs.…
Mitigation only
MEDIUM 6.5
CVE-2025-43838
Missing Authorization vulnerability in ChoPlugins.com Custom PC Builder Lite for WooCommerce custom-pc-builder-lite-for-woocommerce allows Exploiting…
Mitigation only
HIGH 7.5
CVE-2025-39447
Missing Authorization vulnerability in Crocoblock JetElements For Elementor jet-elements allows Accessing Functionality Not Properly Constrained by A…
Mitigation only
MEDIUM 5.3
CVE-2025-39460
Missing Authorization vulnerability in ThimPress Eduma eduma allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…
Mitigation only
MEDIUM 5.4
CVE-2025-22287
Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition ltl-freight-quotes-freightquote-edition allows Exp…
Mitigation only
MEDIUM 5.3
CVE-2025-39388
Missing Authorization vulnerability in Solid Plugins AnalyticsWP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects A…
No fix yet
MEDIUM 5.3
CVE-2025-39373
Missing Authorization vulnerability in jegtheme JNews jnews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect…
Mitigation only
MEDIUM 5.3
CVE-2025-39353
Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security L…
Grand Restaurant
after 7.0
MEDIUM 5.3
CVE-2025-39368
Missing Authorization vulnerability in ed4becky Rootspersona rootspersona allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…
Mitigation only
MEDIUM 5.3
CVE-2025-26867
Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk: from n…
Mitigation only
MEDIUM 5.4
CVE-2025-26920
Missing Authorization vulnerability in pressmaximum Customify customify-theme allows Exploiting Incorrectly Configured Access Control Security Levels…
Mitigation only
MEDIUM 5.3
CVE-2025-48346
Missing Authorization vulnerability in Embed360 Embed and Integrate Etsy Shop embed-and-integrate-etsy-shop allows Accessing Functionality Not Proper…
Mitigation only
MEDIUM 5.3
CVE-2025-48282
Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Sec…
Mitigation only
MEDIUM 5.3
CVE-2025-48272
Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Level…
Wp Job Portal
2.3.3+
MEDIUM 6.5
CVE-2025-48257
Missing Authorization vulnerability in Projectopia Projectopia projectopia-core allows Exploiting Incorrectly Configured Access Control Security Leve…
Mitigation only
MEDIUM 5.4
CVE-2025-48246
Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Secu…
Mitigation only
MEDIUM 6.5
CVE-2025-48242
Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…
Mitigation only
HIGH 7.2
CVE-2025-4477
The ThreatSonar Anti-Ransomware from TeamT5 has a Privilege Escalation vulnerability, allowing remote attackers with intermediate privileges to escal…
Mitigation only
HIGH 8.8
CVE-2025-4887
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1.0. Affected by this issue is…
Online Student Clearance System
No fix yet
MEDIUM 5.4
CVE-2025-3527
The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings…
Eventon
after 4.9.6
HIGH 8.8
CVE-2025-48138
Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly Configured Access Control Sec…
Bertha Ai
after 1.12.11
MEDIUM 6.5
CVE-2025-48127
Missing Authorization vulnerability in App Cheap Push notification for Mobile and Web app push-notification-mobile-and-web-app allows Exploiting Inco…
Mitigation only
MEDIUM 5.3
CVE-2025-48116
Missing Authorization vulnerability in Ashan Perera EventON eventon-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…
Mitigation only
MEDIUM 5.3
CVE-2025-48117
Missing Authorization vulnerability in kilbot WooCommerce POS woocommerce-pos allows Exploiting Incorrectly Configured Access Control Security Levels…
Mitigation only
MEDIUM 5.0
CVE-2025-47560
Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…
Mitigation only