Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2024-12296 The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing cap… Superio after 2.3 Fix from $1,9502025-02-12 MEDIUM 6.5 CVE-2024-13374 The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in… Wp Table Manager 4.1.4+ Fix from $1,6002025-02-12 HIGH 8.1 CVE-2024-13656 The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a de… Click Mag 3.7.0+ Fix from $1,9502025-02-12 MEDIUM 5.4 CVE-2024-13769 The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing… Puzzles 4.2.5+ Fix from $1,6002025-02-12 HIGH 8.1 CVE-2024-13800 The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capabil… Convertplus 3.5.31+ Fix from $1,9502025-02-12 HIGH 8.8 CVE-2024-13653 The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege … Zoxpress 2.12.1+ Fix from $1,9502025-02-12 HIGH 8.1 CVE-2024-13654 The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial o… Zoxpress 2.12.1+ Fix from $1,9502025-02-12 MEDIUM 5.4 CVE-2024-13541 The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check… Adirectory 2.3.5+ Fix from $1,6002025-02-12 MEDIUM 5.3 CVE-2024-13554 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … Wp Extended 3.0.14+ Fix from $1,6002025-02-12 MEDIUM 5.4 CVE-2025-0526 In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked va… Octopus Server 2024.3.13097 / 2024.4.7091+ Fix from $1,6002025-02-11 HIGH 8.8 CVE-2024-13643 The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modification. This vulnerability … Mitigation only Fix from $1,9502025-02-11 MEDIUM 5.4 CVE-2025-25241 Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attac… Mitigation only Fix from $1,6002025-02-11 MEDIUM 5.3 CVE-2025-23187 Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-… Mitigation only Fix from $1,6002025-02-11 CRITICAL 9.8 CVE-2025-25167 Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Contro… Bookpress after 1.2.7 Fix from $2,3002025-02-07 MEDIUM 5.4 CVE-2025-25110 Missing Authorization vulnerability in Metagauss Event Kikfyre kikfyre-events-calendar-tickets allows Exploiting Incorrectly Configured Access Contro… Mitigation only Fix from $1,6002025-02-07 HIGH 7.2 CVE-2025-20125EPSS 17% A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information… Identity Services Engine 3.1+ Fix from $1,9502025-02-05 MEDIUM 6.5 CVE-2024-3976 An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and sta… GitLab 16.9.7 / 16.10.5+ Fix from $1,6002025-02-05 MEDIUM 5.3 CVE-2024-1539 An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starti… GitLab 16.9.7 / 16.10.5+ Fix from $1,6002025-02-05 MEDIUM 6.5 CVE-2025-22730 Missing Authorization vulnerability in ksher thailand Ksher ksher-payment allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… No fix yet Fix from $1,6002025-02-04 MEDIUM 5.4 CVE-2025-22696 Missing Authorization vulnerability in WPDeveloper Document Block – Upload & Embed Docs document.This issue affects Document Block – Upload & Embed D… Mitigation only Fix from $1,6002025-02-04 MEDIUM 6.5 CVE-2024-13529 The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capabil… Mitigation only Fix from $1,6002025-02-04 HIGH 8.8 CVE-2023-52163 KEVEPSS 97% Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer … Ds 2105 Pro Firmware Mitigation only Fix from $1,9502025-02-03 MEDIUM 5.3 CVE-2024-11133 The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' … Eventer after 3.9.9 Fix from $1,6002025-02-03 MEDIUM 6.5 CVE-2024-11134 The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' … Eventer 3.9.9.1+ Fix from $1,6002025-02-03 MEDIUM 6.5 CVE-2025-24697 Missing Authorization vulnerability in Realwebcare Image Gallery – Responsive Photo Gallery awesome-responsive-photo-gallery allows Exploiting Incorr… Mitigation only Fix from $1,6002025-02-03 MEDIUM 6.5 CVE-2025-24642 Missing Authorization vulnerability in theme funda Setup Default Featured Image setup-default-feature-image allows Exploiting Incorrectly Configured … Mitigation only Fix from $1,6002025-02-03 MEDIUM 6.5 CVE-2025-24643 Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Exploiting Incorrectly Configured Access Control Securi… Mitigation only Fix from $1,6002025-02-03 MEDIUM 6.5 CVE-2025-23527 Missing Authorization vulnerability in hemnathmouli WC Wallet wc-wallet allows Accessing Functionality Not Properly Constrained by ACLs.This issue af… Mitigation only Fix from $1,6002025-02-03 MEDIUM 5.3 CVE-2025-22686 Missing Authorization vulnerability in WesternDeal CF7 Google Sheets Connector cf7-google-sheets-connector allows Exploiting Incorrectly Configured A… Mitigation only Fix from $1,6002025-02-03 CRITICAL 9.8 CVE-2024-50500 Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured A… Shortcodes And Extra Features For Phlox Theme 2.17.3+ Fix from $2,3002025-02-03