Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-47563 Missing Authorization vulnerability in villatheme CURCY woocommerce-multi-currency allows Accessing Functionality Not Properly Constrained by ACLs.Th… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-47564 Missing Authorization vulnerability in ashanjay EventON eventon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ev… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.4 CVE-2025-47556 Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Exploiting Incorre… Mitigation only Fix from $1,6002025-05-16 HIGH 8.8 CVE-2025-39482 Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a… Eventer after 3.9.6 Fix from $1,9502025-05-16 HIGH 8.8 CVE-2025-39493 Missing Authorization vulnerability in ValvePress Rankie valvepress-rankie allows Exploiting Incorrectly Configured Access Control Security Levels.Th… Rankie 1.8.2+ Fix from $1,9502025-05-16 MEDIUM 5.3 CVE-2025-32296 Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Co… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.4 CVE-2025-31923 Missing Authorization vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Exploiting Incorrectly Configured Access Con… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-31071 Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Configured Access Control Securi… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-31630 Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affe… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-31065 Missing Authorization vulnerability in themeton Rozario allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects R… No fix yet Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-31066 Missing Authorization vulnerability in themeton Acerola acerola allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af… Mitigation only Fix from $1,6002025-05-16 MEDIUM 6.1 CVE-2025-47792 Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed o… Desktop 3.15.0+ Fix from $1,6002025-05-16 HIGH 7.5 CVE-2024-12812 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDO… Wp Erp 1.13.4+ Fix from $1,9502025-05-15 MEDIUM 5.3 CVE-2024-56006 Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a before 2.0.1. Mitigation only Fix from $1,6002025-05-15 CRITICAL 9.8 CVE-2025-47580 Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Securi… Front End Users after 3.2.32 Fix from $2,3002025-05-15 HIGH 8.1 CVE-2024-58101 Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequenc… Mitigation only Fix from $1,9502025-05-14 MEDIUM 6.5 CVE-2025-47709 Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Dr… Miniorange 2fa 5.2.0 / 8.x-4.7+ Fix from $1,6002025-05-14 MEDIUM 5.0 CVE-2025-24021 iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set valu… Itop 2.7.12 / 3.1.3+ Fix from $1,6002025-05-14 HIGH 8.6 CVE-2025-4430 Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in versions before 20.19 (publishe… Mitigation only Fix from $1,9502025-05-14 HIGH 7.7 CVE-2025-43011 Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated… Mitigation only Fix from $1,9502025-05-13 MEDIUM 5.3 CVE-2025-43004 Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enable outside users to access cus… Mitigation only Fix from $1,6002025-05-13 MEDIUM 6.3 CVE-2025-43007 SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privil… Mitigation only Fix from $1,6002025-05-13 MEDIUM 5.8 CVE-2025-43008 Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of emplo… Mitigation only Fix from $1,6002025-05-13 MEDIUM 6.3 CVE-2025-43009 SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privil… Mitigation only Fix from $1,6002025-05-13 HIGH 7.9 CVE-2025-43000 Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High… Mitigation only Fix from $1,9502025-05-13 CRITICAL 9.1 CVE-2025-30448 This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macO… Ipados 2.5 / 13.7.6+ Fix from $2,3002025-05-12 MEDIUM 6.5 CVE-2025-46745 An authenticated user without user-management permissions could view other users account information. Mitigation only Fix from $1,6002025-05-12 CRITICAL 9.8 CVE-2025-26846 An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata. Znuny after 7.1.3 Fix from $2,3002025-05-12 HIGH 8.8 CVE-2025-3876 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in… Sms Alert Order Notifications 3.8.2+ Fix from $1,9502025-05-10 HIGH 8.8 CVE-2025-28202 Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication. Rx1800 Firmware No fix yet Fix from $1,9502025-05-09