Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2025-30887
Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Leve…
Mitigation only
MEDIUM 5.3
CVE-2025-30866
Missing Authorization vulnerability in Giannis Kipouros Terms & Conditions Per Product terms-and-conditions-per-product allows Exploiting Incorrectly…
Mitigation only
MEDIUM 5.3
CVE-2025-30839
Missing Authorization vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Exploiting Incorrectly Co…
Mitigation only
MEDIUM 5.3
CVE-2025-30828
Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…
Mitigation only
MEDIUM 5.3
CVE-2025-30830
Missing Authorization vulnerability in Hossni Mubarak Cool Author Box hm-cool-author-box-widget allows Exploiting Incorrectly Configured Access Contr…
Mitigation only
MEDIUM 5.3
CVE-2025-30821
Missing Authorization vulnerability in otacke SNORDIAN's H5PxAPIkatchu h5pxapikatchu allows Accessing Functionality Not Properly Constrained by ACLs.…
Mitigation only
MEDIUM 5.4
CVE-2025-30824
Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access Control Security Levels.This i…
Mitigation only
MEDIUM 5.4
CVE-2025-30817
Missing Authorization vulnerability in wpzita Z Companion z-companion allows Exploiting Incorrectly Configured Access Control Security Levels.This is…
Mitigation only
MEDIUM 5.4
CVE-2025-30809
Missing Authorization vulnerability in Shahjada Live Forms liveforms allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…
Mitigation only
MEDIUM 5.3
CVE-2025-30790
Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Accessing Functionality Not Properly Constrained by ACLs.Thi…
Mitigation only
HIGH 8.8
CVE-2025-30772
Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce wpc-smart-upsell-funnel allows Privilege Escalation.This issu…
Mitigation only
MEDIUM 5.4
CVE-2025-30767
Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security L…
Mitigation only
HIGH 8.8
CVE-2025-2110
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data …
Wp Compress
6.30.16+
HIGH 8.1
CVE-2024-13801
The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a mi…
Mitigation only
MEDIUM 5.3
CVE-2025-2224
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and mod…
Mitigation only
MEDIUM 5.3
CVE-2025-30591
Missing Authorization vulnerability in tuyennv Music Press Pro music-press-pro allows Exploiting Incorrectly Configured Access Control Security Level…
No fix yet
MEDIUM 5.3
CVE-2025-30592
Missing Authorization vulnerability in WesternDeal Advanced Dewplayer advanced-dewplayer allows Exploiting Incorrectly Configured Access Control Secu…
Mitigation only
MEDIUM 5.3
CVE-2025-30581
Missing Authorization vulnerability in PluginOps Top Bar ultimate-bar allows Exploiting Incorrectly Configured Access Control Security Levels.This is…
Mitigation only
CRITICAL 9.8
CVE-2025-2589
A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index o…
Human Resource Management
No fix yet
CRITICAL 9.8
CVE-2025-26853
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
Infocad
3.5.2.0+
CRITICAL 9.8
CVE-2024-9095
In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Googl…
Lunary
Patch available
HIGH 7.1
CVE-2024-9096
In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending a PATCH request. The route l…
Lunary
Patch available
HIGH 7.5
CVE-2024-8999
lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnera…
Lunary
1.4.26+
MEDIUM 6.5
CVE-2024-9000
In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the …
Lunary
Patch available
HIGH 8.1
CVE-2024-7767
An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system…
Onyx
No fix yet
HIGH 8.8
CVE-2024-7043
An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not veri…
Open Webui
No fix yet
HIGH 7.1
CVE-2024-2292
Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users.
Mitigation only
HIGH 8.1
CVE-2024-10762
In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by sending a DELETE request. Ho…
Lunary
1.5.9+
MEDIUM 6.5
CVE-2024-10330
In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch a…
Lunary
1.5.7+
MEDIUM 5.4
CVE-2024-10363
In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being …
Librechat
Patch available