Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-27013 Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Incorrectly Configured Access Con… Mitigation only Fix from $1,6002025-02-18 HIGH 7.5 CVE-2025-22657 Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security… Mitigation only Fix from $1,9502025-02-18 MEDIUM 5.3 CVE-2024-13316 The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable … Scratch \& Win 2.9.0+ Fix from $1,6002025-02-18 CRITICAL 9.8 CVE-2024-13556 The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all version… Affiliate Links 3.1.0+ Fix from $2,3002025-02-18 HIGH 8.8 CVE-2024-13677 The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege escalation via account takeove… Get Bookings Wp after 1.1.27 Fix from $1,9502025-02-18 HIGH 8.8 CVE-2025-26773 Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… Analytify Google Analytics Dashboard 5.5.1+ Fix from $1,9502025-02-17 MEDIUM 5.4 CVE-2025-26765 Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Exploiting Inco… Mitigation only Fix from $1,6002025-02-16 CRITICAL 9.8 CVE-2025-22289 Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Unishippers Edition ltl-freight-quotes-unishippers-edition allows Explo… Ltl Freight Quotes 2.5.9+ Fix from $2,3002025-02-16 MEDIUM 5.3 CVE-2025-22291 Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition ltl-freight-quotes-worldwide-express-edition … Mitigation only Fix from $1,6002025-02-16 MEDIUM 6.5 CVE-2024-13752 The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unau… Wp Project Manager 2.6.18+ Fix from $1,6002025-02-15 CRITICAL 9.8 CVE-2024-13513 The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… Oliver Pos 2.4.2.4+ Fix from $2,3002025-02-15 HIGH 7.1 CVE-2025-24692 Missing Authorization vulnerability in M.Code Bulk Menu Edit bulk-menu-edit allows Exploiting Incorrectly Configured Access Control Security Levels.T… Mitigation only Fix from $1,9502025-02-14 CRITICAL 9.8 CVE-2025-24607 Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configured Access Control Security L… Ideapush 8.73+ Fix from $2,3002025-02-14 MEDIUM 6.5 CVE-2025-23766 Missing Authorization vulnerability in ashamil OPSI Israel Domestic Shipments woo-ups-pickup allows Exploiting Incorrectly Configured Access Control … Mitigation only Fix from $1,6002025-02-14 MEDIUM 6.5 CVE-2025-23771 Missing Authorization vulnerability in Murali Push Notification for Post and BuddyPress push-notification-for-post-and-buddypress allows Exploiting I… Mitigation only Fix from $1,6002025-02-14 MEDIUM 6.5 CVE-2025-23534 Missing Authorization vulnerability in Mark Winiarski WPLingo wplingo allows Exploiting Incorrectly Configured Access Control Security Levels.This is… Mitigation only Fix from $1,6002025-02-14 HIGH 7.2 CVE-2024-52500 Missing Authorization vulnerability in monetagwp Monetag Official Plugin monetag-official allows Exploiting Incorrectly Configured Access Control Sec… Mitigation only Fix from $1,9502025-02-14 MEDIUM 6.3 CVE-2025-22698 Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrectly Configured Access Control … Mitigation only Fix from $1,6002025-02-14 MEDIUM 6.3 CVE-2025-22702 Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… No fix yet Fix from $1,6002025-02-14 HIGH 8.8 CVE-2025-1214 A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of th… Maxair No fix yet Fix from $1,9502025-02-12 HIGH 8.8 CVE-2025-26378 A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-… Maxtime after 2.11.0 Fix from $1,9502025-02-12 HIGH 8.8 CVE-2025-26371 A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated… Maxtime after 2.11.0 Fix from $1,9502025-02-12 HIGH 8.1 CVE-2025-26372 A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated… Maxtime after 2.11.0 Fix from $1,9502025-02-12 MEDIUM 6.5 CVE-2025-26373 A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an aut… Maxtime after 2.11.0 Fix from $1,6002025-02-12 HIGH 8.8 CVE-2025-26375 A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-… Maxtime after 2.11.0 Fix from $1,9502025-02-12 MEDIUM 6.5 CVE-2025-26376 A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-… Maxtime after 2.11.0 Fix from $1,6002025-02-12 HIGH 8.1 CVE-2025-26377 A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-… Maxtime after 2.11.0 Fix from $1,9502025-02-12 HIGH 8.1 CVE-2025-26368 A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated… Maxtime after 2.11.0 Fix from $1,9502025-02-12 HIGH 8.8 CVE-2025-26369 A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated… Maxtime after 2.11.0 Fix from $1,9502025-02-12 HIGH 7.1 CVE-2025-26370 A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated… Maxtime after 2.11.0 Fix from $1,9502025-02-12