Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.8 CVE-2025-24181 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.… macOS 13.7.5 / 14.7.5+ Fix from $2,3002025-03-31 CRITICAL 9.1 CVE-2025-31685 Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12… Open Social 12.3.11 / 12.4.10+ Fix from $2,3002025-03-31 HIGH 8.1 CVE-2025-31686 Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12… Open Social 12.3.11 / 12.4.10+ Fix from $1,9502025-03-31 CRITICAL 9.8 CVE-2025-31691 Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0. Oauth2 Server 2.1.0+ Fix from $2,3002025-03-31 HIGH 8.2 CVE-2025-31678 Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): … Artificial Intelligence 1.0.3+ Fix from $1,9502025-03-31 CRITICAL 9.8 CVE-2025-31681 Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before … Authenticator Login 2.0.6+ Fix from $2,3002025-03-31 MEDIUM 5.3 CVE-2025-31618 Missing Authorization vulnerability in Jaap Jansma Connector to CiviCRM with CiviMcRestFace connector-civicrm-mcrestface allows Exploiting Incorrectl… Mitigation only Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-31603 Missing Authorization vulnerability in moshensky CF7 Spreadsheets cf7-spreadsheets allows Exploiting Incorrectly Configured Access Control Security L… Mitigation only Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-31584 Missing Authorization vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Exploiting Incorrectly Configured Ac… Mitigation only Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-31555 Missing Authorization vulnerability in ContentMX ContentMX Content Publisher contentmx-content-publisher allows Exploiting Incorrectly Configured Acc… Mitigation only Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-31545 Missing Authorization vulnerability in WP Messiah Safe Ai Malware Protection for WP safe-ai-malware-protection-for-wp allows Exploiting Incorrectly C… Mitigation only Fix from $1,6002025-03-31 MEDIUM 5.3 CVE-2025-31533 Missing Authorization vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms gf-salesmate-add-on allows Accessing Functionality Not Properl… Mitigation only Fix from $1,6002025-03-31 MEDIUM 6.5 CVE-2025-31539 Missing Authorization vulnerability in Blocksera Cryptocurrency Widgets Pack cryptocurrency-widgets-pack allows Exploiting Incorrectly Configured Acc… Mitigation only Fix from $1,6002025-03-31 MEDIUM 5.3 CVE-2025-31386 Missing Authorization vulnerability in simplepress Simple:Press simplepress allows Exploiting Incorrectly Configured Access Control Security Levels.T… Mitigation only Fix from $1,6002025-03-31 HIGH 7.5 CVE-2025-30855 Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Exploiting Incorrectly Configured Access Control S… Mitigation only Fix from $1,9502025-03-31 CRITICAL 9.8 CVE-2025-2266 The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat… Mitigation only Fix from $2,3002025-03-29 MEDIUM 5.3 CVE-2025-31469 Missing Authorization vulnerability in webrangers Clear Sucuri Cache clear-sucuri-cache allows Exploiting Incorrectly Configured Access Control Secur… Mitigation only Fix from $1,6002025-03-28 HIGH 8.8 CVE-2025-2815 The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing ca… Mitigation only Fix from $1,9502025-03-28 HIGH 8.2 CVE-2025-26733 Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1. Mitigation only Fix from $1,9502025-03-27 HIGH 7.6 CVE-2025-26956 Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1. Mitigation only Fix from $1,9502025-03-27 MEDIUM 5.3 CVE-2025-22739 Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This i… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.3 CVE-2025-22740 Missing Authorization vulnerability in Automattic Sensei LMS sensei-lms allows Exploiting Incorrectly Configured Access Control Security Levels.This … Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.4 CVE-2024-55072 A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profi… Mealie No fix yet Fix from $1,6002025-03-27 HIGH 7.6 CVE-2024-55073 A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profi… Mealie No fix yet Fix from $1,9502025-03-27 MEDIUM 5.3 CVE-2025-22629 Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect… Mitigation only Fix from $1,6002025-03-27 MEDIUM 6.5 CVE-2025-22670 Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Exploiting Incorrectly Configured Access Cont… Mitigation only Fix from $1,6002025-03-27 MEDIUM 6.5 CVE-2025-22668 Missing Authorization vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Exploiting Incorrectly Configured Access Contro… No fix yet Fix from $1,6002025-03-27 MEDIUM 5.4 CVE-2025-22770 Missing Authorization vulnerability in EnvoThemes Envo Multipurpose allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… No fix yet Fix from $1,6002025-03-27 MEDIUM 5.4 CVE-2025-30896 Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects W… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.4 CVE-2025-30881 Missing Authorization vulnerability in themehunk Big Store big-store allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… Big Store 2.0.9+ Fix from $1,6002025-03-27