Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-30887 Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Leve… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.3 CVE-2025-30866 Missing Authorization vulnerability in Giannis Kipouros Terms & Conditions Per Product terms-and-conditions-per-product allows Exploiting Incorrectly… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.3 CVE-2025-30839 Missing Authorization vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Exploiting Incorrectly Co… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.3 CVE-2025-30828 Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.3 CVE-2025-30830 Missing Authorization vulnerability in Hossni Mubarak Cool Author Box hm-cool-author-box-widget allows Exploiting Incorrectly Configured Access Contr… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.3 CVE-2025-30821 Missing Authorization vulnerability in otacke SNORDIAN's H5PxAPIkatchu h5pxapikatchu allows Accessing Functionality Not Properly Constrained by ACLs.… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.4 CVE-2025-30824 Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access Control Security Levels.This i… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.4 CVE-2025-30817 Missing Authorization vulnerability in wpzita Z Companion z-companion allows Exploiting Incorrectly Configured Access Control Security Levels.This is… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.4 CVE-2025-30809 Missing Authorization vulnerability in Shahjada Live Forms liveforms allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… Mitigation only Fix from $1,6002025-03-27 MEDIUM 5.3 CVE-2025-30790 Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Accessing Functionality Not Properly Constrained by ACLs.Thi… Mitigation only Fix from $1,6002025-03-27 HIGH 8.8 CVE-2025-30772 Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce wpc-smart-upsell-funnel allows Privilege Escalation.This issu… Mitigation only Fix from $1,9502025-03-27 MEDIUM 5.4 CVE-2025-30767 Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security L… Mitigation only Fix from $1,6002025-03-27 HIGH 8.8 CVE-2025-2110 The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data … Wp Compress 6.30.16+ Fix from $1,9502025-03-26 HIGH 8.1 CVE-2024-13801 The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a mi… Mitigation only Fix from $1,9502025-03-26 MEDIUM 5.3 CVE-2025-2224 The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and mod… Mitigation only Fix from $1,6002025-03-25 MEDIUM 5.3 CVE-2025-30591 Missing Authorization vulnerability in tuyennv Music Press Pro music-press-pro allows Exploiting Incorrectly Configured Access Control Security Level… No fix yet Fix from $1,6002025-03-24 MEDIUM 5.3 CVE-2025-30592 Missing Authorization vulnerability in WesternDeal Advanced Dewplayer advanced-dewplayer allows Exploiting Incorrectly Configured Access Control Secu… Mitigation only Fix from $1,6002025-03-24 MEDIUM 5.3 CVE-2025-30581 Missing Authorization vulnerability in PluginOps Top Bar ultimate-bar allows Exploiting Incorrectly Configured Access Control Security Levels.This is… Mitigation only Fix from $1,6002025-03-24 CRITICAL 9.8 CVE-2025-2589 A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index o… Human Resource Management No fix yet Fix from $2,3002025-03-21 CRITICAL 9.8 CVE-2025-26853 DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema. Infocad 3.5.2.0+ Fix from $2,3002025-03-20 CRITICAL 9.8 CVE-2024-9095 In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Googl… Lunary Patch available Fix from $2,3002025-03-20 HIGH 7.1 CVE-2024-9096 In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending a PATCH request. The route l… Lunary Patch available Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-8999 lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnera… Lunary 1.4.26+ Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-9000 In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the … Lunary Patch available Fix from $1,6002025-03-20 HIGH 8.1 CVE-2024-7767 An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system… Onyx No fix yet Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-7043 An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not veri… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.1 CVE-2024-2292 Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users. Mitigation only Fix from $1,9502025-03-20 HIGH 8.1 CVE-2024-10762 In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by sending a DELETE request. Ho… Lunary 1.5.9+ Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-10330 In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch a… Lunary 1.5.7+ Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-10363 In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being … Librechat Patch available Fix from $1,6002025-03-20