Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.3 CVE-2025-20164 A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to el… Mitigation only Fix from $1,9502025-05-07 CRITICAL 9.8 CVE-2025-47688 Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control… Advanced File Manager 5.3.2+ Fix from $2,3002025-05-07 HIGH 8.8 CVE-2025-47628 Missing Authorization vulnerability in quomodosoft QS Dark Mode qs-dark-mode allows Exploiting Incorrectly Configured Access Control Security Levels.… Qs Dark Mode after 3.0 Fix from $1,9502025-05-07 HIGH 8.8 CVE-2025-47612 Missing Authorization vulnerability in ClickWhale ClickWhale clickwhale allows Exploiting Incorrectly Configured Access Control Security Levels.This … Clickwhale 2.4.7+ Fix from $1,9502025-05-07 MEDIUM 5.4 CVE-2025-47602 Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce calculate-prices-based-on-distance-for-woocom… Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.4 CVE-2025-47526 Missing Authorization vulnerability in GS Plugins GS Variation Swatches for WooCommerce gs-woo-variation-swatches allows Exploiting Incorrectly Confi… Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.4 CVE-2025-47480 Missing Authorization vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows Exploiting Incorrectly Configured Access Co… No fix yet Fix from $1,6002025-05-07 MEDIUM 5.3 CVE-2025-47485 Missing Authorization vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.3 CVE-2025-47486 Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Accessing Functionality Not Properly Constrained by ACLs… Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.4 CVE-2025-47469 Missing Authorization vulnerability in slui Media Hygiene media-hygiene allows Exploiting Incorrectly Configured Access Control Security Levels.This … Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.4 CVE-2025-47472 Missing Authorization vulnerability in codepeople Music Player for WooCommerce music-player-for-woocommerce allows Exploiting Incorrectly Configured … Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.3 CVE-2025-47450 Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Secu… No fix yet Fix from $1,6002025-05-07 MEDIUM 5.3 CVE-2025-47457 Missing Authorization vulnerability in dgamoni LocateAndFilter locateandfilter allows Accessing Functionality Not Properly Constrained by ACLs.This i… No fix yet Fix from $1,6002025-05-07 MEDIUM 5.4 CVE-2025-3766 The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_too… Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.3 CVE-2025-2821 The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_rest_permissi… Mitigation only Fix from $1,6002025-05-07 HIGH 7.3 CVE-2025-0856 The PGS Core plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple … Mitigation only Fix from $1,9502025-05-06 MEDIUM 5.5 CVE-2025-46586 Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002025-05-06 HIGH 8.8 CVE-2025-4282 A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unkn… Stock Management System No fix yet Fix from $1,9502025-05-05 CRITICAL 9.8 CVE-2025-3927 Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to conne… Pyko Out Mitigation only Fix from $2,3002025-05-02 MEDIUM 5.4 CVE-2024-13419 Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on… April after 7.1 Fix from $1,6002025-05-02 MEDIUM 5.3 CVE-2025-4177 The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteUser() function in a… Flynax Bridge after 2.2.0 Fix from $1,6002025-05-02 HIGH 7.3 CVE-2025-4179 The Flynax Bridge plugin for WordPress is vulnerable to limited Privilege Escalation due to a missing capability check on the registerUser() function… Flynax Bridge after 2.2.0 Fix from $1,9502025-05-02 CRITICAL 9.8 CVE-2025-3746 The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.14 to 2.0.59. This is du… Mitigation only Fix from $2,3002025-05-02 HIGH 8.1 CVE-2025-3952 The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of s… Projectopia 5.1.17+ Fix from $1,9502025-05-01 HIGH 8.8 CVE-2025-1304 The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate… Newsblogger 0.2.5.2+ Fix from $1,9502025-05-01 HIGH 8.1 CVE-2025-2816 The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing cap… Page View Count 2.8.5+ Fix from $1,9502025-05-01 MEDIUM 5.3 CVE-2025-46554 XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 1… Xwiki 14.10.22 / 15.10.12+ Fix from $1,6002025-04-30 CRITICAL 9.8 CVE-2025-46557 XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to … Xwiki 15.10.14 / 16.4.6+ Fix from $2,3002025-04-30 HIGH 8.8 CVE-2025-39413 Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This issue affects Simple Sitemap… Simple Sitemap after 3.6.0 Fix from $1,9502025-04-30 HIGH 8.8 CVE-2025-21416 Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. Azure Virtual Desktop Mitigation only Fix from $1,9502025-04-30