Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.0 CVE-2025-32973 XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to … Xwiki 15.10.12 / 16.4.3+ Fix from $2,3002025-04-30 MEDIUM 5.4 CVE-2025-3953 The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to… Mitigation only Fix from $1,6002025-04-30 CRITICAL 9.8 CVE-2025-46348 YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authen… Yeswiki 4.5.4+ Fix from $2,3002025-04-29 MEDIUM 5.3 CVE-2025-4064 A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file … Online Traveling System Mitigation only Fix from $1,6002025-04-29 MEDIUM 5.3 CVE-2025-39367 Missing Authorization vulnerability in SeventhQueen Kleo kleo.This issue affects Kleo: from n/a through < 5.4.4. No fix yet Fix from $1,6002025-04-28 MEDIUM 5.3 CVE-2025-3981 A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. T… Internet Doctor Workstation System No fix yet Fix from $1,6002025-04-27 MEDIUM 6.5 CVE-2025-3979 A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-aja… Lecms No fix yet Fix from $1,6002025-04-27 MEDIUM 5.3 CVE-2025-3980 A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This vulnerability… Internet Doctor Workstation System No fix yet Fix from $1,6002025-04-27 CRITICAL 9.8 CVE-2025-3963 A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processin… Books Management System No fix yet Fix from $2,3002025-04-27 CRITICAL 9.8 CVE-2025-3960 A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionali… Books Management System No fix yet Fix from $2,3002025-04-27 HIGH 8.8 CVE-2025-3906 The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… Mitigation only Fix from $1,9502025-04-26 HIGH 7.6 CVE-2025-43862 Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even thou… Dify 0.6.12+ Fix from $1,9502025-04-25 MEDIUM 5.3 CVE-2025-32045 A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to… Moodle 4.1.17 / 4.3.11+ Fix from $1,6002025-04-25 MEDIUM 5.3 CVE-2025-3912 The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing … Mitigation only Fix from $1,6002025-04-25 HIGH 8.8 CVE-2025-1279 The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing… Mitigation only Fix from $1,9502025-04-25 MEDIUM 5.4 CVE-2025-46535 Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Secu… No fix yet Fix from $1,6002025-04-25 MEDIUM 5.3 CVE-2025-46485 Missing Authorization vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Accessing Functionality Not Properly Cons… Mitigation only Fix from $1,6002025-04-24 MEDIUM 5.3 CVE-2025-46489 Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce wc-bulk-assign-linked-products allows Accessing Func… Mitigation only Fix from $1,6002025-04-24 MEDIUM 5.3 CVE-2025-39390 Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Function… Mitigation only Fix from $1,6002025-04-24 HIGH 7.5 CVE-2021-47662 Due to missing authorization an unauthenticated remote attacker can cause a DoS attack by connecting via HTTPS and triggering the shutdown button. Mitigation only Fix from $1,9502025-04-24 CRITICAL 9.8 CVE-2025-3604 The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This i… Flynax Bridge after 2.2.0 Fix from $2,3002025-04-24 HIGH 8.8 CVE-2025-3058 The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing cap… Mitigation only Fix from $1,9502025-04-24 MEDIUM 5.3 CVE-2024-13307 The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capabili… Mitigation only Fix from $1,6002025-04-24 HIGH 7.5 CVE-2025-1021 Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows re… Diskstation Manager 7.1.1-42962-8 / 7.2.1-69057-7+ Fix from $1,9502025-04-23 CRITICAL 9.8 CVE-2025-37087 A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the … Mitigation only Fix from $2,3002025-04-22 CRITICAL 9.8 CVE-2025-46247 Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Proper… Appointment Booking Calendar 1.3.93+ Fix from $2,3002025-04-22 CRITICAL 9.8 CVE-2025-46244 Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Exploiting Incorrectly Configured … Advanced Linked Variations For Woocommerce 1.0.4+ Fix from $2,3002025-04-22 HIGH 8.8 CVE-2025-46232 Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Lev… Alt Text Ai 1.9.94+ Fix from $1,9502025-04-22 MEDIUM 6.5 CVE-2025-3843 A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to… Ds Java No fix yet Fix from $1,6002025-04-21 MEDIUM 6.4 CVE-2025-28103 Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request. Flaskblog Mitigation only Fix from $1,6002025-04-21