Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.5 CVE-2024-10272 lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of au… Lunary 1.4.9+ Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-10274 An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequate access control mechanisms… Lunary 1.5.7+ Fix from $1,6002025-03-20 MEDIUM 5.3 CVE-2025-1766 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a… Eventin 4.0.25+ Fix from $1,6002025-03-20 CRITICAL 9.8 CVE-2025-29926 XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki… Xwiki 15.10.15 / 16.4.6+ Fix from $2,3002025-03-19 HIGH 8.8 CVE-2024-12920 The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of d… Mitigation only Fix from $1,9502025-03-19 HIGH 7.5 CVE-2024-13412 The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in… Mitigation only Fix from $1,9502025-03-19 CRITICAL 9.8 CVE-2024-12922 The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability c… Mitigation only Fix from $2,3002025-03-19 MEDIUM 5.3 CVE-2025-2290 The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing … Lifterlms 8.0.2+ Fix from $1,6002025-03-19 HIGH 7.5 CVE-2025-30107 On IROAD V9 devices, Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. A vulner… Mitigation only Fix from $1,9502025-03-18 HIGH 7.3 CVE-2025-2262 The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortco… Mitigation only Fix from $1,9502025-03-18 HIGH 8.3 CVE-2025-26969 Missing Authorization vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5. Mitigation only Fix from $1,9502025-03-15 HIGH 8.6 CVE-2025-26961 Missing Authorization vulnerability in FRESHFACE Fresh Framework fresh-framework allows Accessing Functionality Not Properly Constrained by ACLs.This… Mitigation only Fix from $1,9502025-03-15 HIGH 7.5 CVE-2025-2025 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… Givewp 3.22.1+ Fix from $1,9502025-03-15 MEDIUM 6.5 CVE-2025-2267 The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check … Wp01 after 2.6.2 Fix from $1,6002025-03-15 MEDIUM 5.4 CVE-2025-1668 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the w… Wpschoolpress after 2.2.16 Fix from $1,6002025-03-15 MEDIUM 6.5 CVE-2024-12336 The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil… Wc Affiliate 2.6+ Fix from $1,6002025-03-15 HIGH 8.8 CVE-2025-1657 The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection d… Ulisting after 2.1.7 Fix from $1,9502025-03-15 HIGH 8.1 CVE-2024-12810 The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to … Jobcareer after 7.1 Fix from $1,9502025-03-14 MEDIUM 5.3 CVE-2025-1507 The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… Dashboard For Google Analytics 3.2.2+ Fix from $1,6002025-03-14 HIGH 8.8 CVE-2025-2103 The SoundRise Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing ca… Soundrise 1.7.1+ Fix from $1,9502025-03-14 HIGH 8.8 CVE-2025-2289 The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX endpoin… Zegen after 1.1.9 Fix from $1,9502025-03-14 HIGH 8.1 CVE-2025-0952 The Eco Nature - Environment & Ecology WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a deni… Mitigation only Fix from $1,9502025-03-14 MEDIUM 5.3 CVE-2025-0955 The VidoRev Extensions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'vidorev_import_single_vide… Mitigation only Fix from $1,6002025-03-14 MEDIUM 5.3 CVE-2025-1285 The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api… Mitigation only Fix from $1,6002025-03-14 MEDIUM 6.5 CVE-2025-24974 DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize a… Dataease 2.10.6+ Fix from $1,6002025-03-13 MEDIUM 6.5 CVE-2025-27103 DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allo… Dataease 2.10.6+ Fix from $1,6002025-03-13 MEDIUM 5.3 CVE-2025-1508 The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action i… Wp Crowdfunding after 2.1.13 Fix from $1,6002025-03-12 MEDIUM 5.3 CVE-2025-28920 Missing Authorization vulnerability in Jogesh Responsive Google Map responsive-google-map allows Exploiting Incorrectly Configured Access Control Sec… Mitigation only Fix from $1,6002025-03-11 CRITICAL 9.8 CVE-2025-28872 Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Accessing Functionality Not Properly C… Block Spam By Math Reloaded after 2.2.4 Fix from $2,3002025-03-11 HIGH 8.8 CVE-2025-26661 Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulti… Mitigation only Fix from $1,9502025-03-11