Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.4 CVE-2025-4105 The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions in the 'spl… Mitigation only Fix from $1,6002025-05-21 HIGH 7.3 CVE-2025-41231 VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be abl… Cloud Foundation 4.5.2 / 5.2.1.2+ Fix from $1,9502025-05-20 HIGH 8.2 CVE-2025-39350 Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0. Mitigation only Fix from $1,9502025-05-19 HIGH 8.2 CVE-2025-39352 Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security L… Grand Restaurant after 7.0 Fix from $1,9502025-05-19 HIGH 7.5 CVE-2025-39449 Missing Authorization vulnerability in Crocoblock JetWooBuilder jet-woo-builder allows Accessing Functionality Not Properly Constrained by ACLs.This … Mitigation only Fix from $1,9502025-05-19 HIGH 7.5 CVE-2025-39451 Missing Authorization vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Accessing Functionality Not Properly Constrained by ACLs.… Mitigation only Fix from $1,9502025-05-19 MEDIUM 6.5 CVE-2025-43838 Missing Authorization vulnerability in ChoPlugins.com Custom PC Builder Lite for WooCommerce custom-pc-builder-lite-for-woocommerce allows Exploiting… Mitigation only Fix from $1,6002025-05-19 HIGH 7.5 CVE-2025-39447 Missing Authorization vulnerability in Crocoblock JetElements For Elementor jet-elements allows Accessing Functionality Not Properly Constrained by A… Mitigation only Fix from $1,9502025-05-19 MEDIUM 5.3 CVE-2025-39460 Missing Authorization vulnerability in ThimPress Eduma eduma allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.4 CVE-2025-22287 Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition ltl-freight-quotes-freightquote-edition allows Exp… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.3 CVE-2025-39388 Missing Authorization vulnerability in Solid Plugins AnalyticsWP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects A… No fix yet Fix from $1,6002025-05-19 MEDIUM 5.3 CVE-2025-39373 Missing Authorization vulnerability in jegtheme JNews jnews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.3 CVE-2025-39353 Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security L… Grand Restaurant after 7.0 Fix from $1,6002025-05-19 MEDIUM 5.3 CVE-2025-39368 Missing Authorization vulnerability in ed4becky Rootspersona rootspersona allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.3 CVE-2025-26867 Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk: from n… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.4 CVE-2025-26920 Missing Authorization vulnerability in pressmaximum Customify customify-theme allows Exploiting Incorrectly Configured Access Control Security Levels… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.3 CVE-2025-48346 Missing Authorization vulnerability in Embed360 Embed and Integrate Etsy Shop embed-and-integrate-etsy-shop allows Accessing Functionality Not Proper… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.3 CVE-2025-48282 Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Sec… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.3 CVE-2025-48272 Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Level… Wp Job Portal 2.3.3+ Fix from $1,6002025-05-19 MEDIUM 6.5 CVE-2025-48257 Missing Authorization vulnerability in Projectopia Projectopia projectopia-core allows Exploiting Incorrectly Configured Access Control Security Leve… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.4 CVE-2025-48246 Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Secu… Mitigation only Fix from $1,6002025-05-19 MEDIUM 6.5 CVE-2025-48242 Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… Mitigation only Fix from $1,6002025-05-19 HIGH 7.2 CVE-2025-4477 The ThreatSonar Anti-Ransomware from TeamT5 has a Privilege Escalation vulnerability, allowing remote attackers with intermediate privileges to escal… Mitigation only Fix from $1,9502025-05-19 HIGH 8.8 CVE-2025-4887 A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1.0. Affected by this issue is… Online Student Clearance System No fix yet Fix from $1,9502025-05-18 MEDIUM 5.4 CVE-2025-3527 The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings… Eventon after 4.9.6 Fix from $1,6002025-05-17 HIGH 8.8 CVE-2025-48138 Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly Configured Access Control Sec… Bertha Ai after 1.12.11 Fix from $1,9502025-05-16 MEDIUM 6.5 CVE-2025-48127 Missing Authorization vulnerability in App Cheap Push notification for Mobile and Web app push-notification-mobile-and-web-app allows Exploiting Inco… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-48116 Missing Authorization vulnerability in Ashan Perera EventON eventon-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue a… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-48117 Missing Authorization vulnerability in kilbot WooCommerce POS woocommerce-pos allows Exploiting Incorrectly Configured Access Control Security Levels… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.0 CVE-2025-47560 Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… Mitigation only Fix from $1,6002025-05-16