Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2024-13775
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on …
Woocommerce Support Ticket System
17.9+
MEDIUM 5.3
CVE-2024-13371
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary email…
Wp Job Portal
2.2.7+
MEDIUM 5.4
CVE-2024-12825
The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three …
Custom Related Posts
1.7.4+
MEDIUM 6.3
CVE-2025-0939
The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in…
Magicform
after 1.6.2
HIGH 8.8
CVE-2024-12171
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check …
Wsdesk
3.2.7+
MEDIUM 5.3
CVE-2024-12184
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the acc…
Wordpress Contact Forms
1.9.5+
MEDIUM 5.3
CVE-2024-12620
The AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations plugin for WordPress is vulnerable to unauthorized modification of d…
Animategl Animations
after 1.4.23
HIGH 8.8
CVE-2024-13343
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new…
Woocommerce Customers Manager
31.4+
MEDIUM 6.5
CVE-2025-22265
Missing Authorization vulnerability in mgplugin EMI Calculator emi-calculator allows Exploiting Incorrectly Configured Access Control Security Levels…
Mitigation only
MEDIUM 5.8
CVE-2025-22720
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorre…
Mitigation only
HIGH 8.1
CVE-2024-13767
The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() functi…
Mitigation only
CRITICAL 9.8
CVE-2024-12822
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a …
Media Manager
after 3.11.0
MEDIUM 6.5
CVE-2024-12821
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a …
Media Manager
after 3.12.0
HIGH 8.8
CVE-2024-12129
The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capabil…
Royal Core
after 2.9.2
HIGH 7.5
CVE-2024-12269
The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the expo…
Safe Ai Malware Protection For Wp
after 1.0.17
HIGH 8.8
CVE-2024-10591
The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for WordPress is vulnerable to unauth…
Hubspot For Woocommerce
1.6.0+
HIGH 8.2
CVE-2025-21396
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
Account
No fix yet
HIGH 8.4
CVE-2024-40677
In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission …
Android
Mitigation only
MEDIUM 6.5
CVE-2025-24143
The issue was addressed with improved access restrictions to the file system. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Seq…
Safari
2.3 / 15.3+
MEDIUM 5.5
CVE-2025-24108
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected…
macOS
15.3+
MEDIUM 5.5
CVE-2025-24096
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. A malicious app may be able to access arbitrar…
macOS
15.3+
CRITICAL 9.1
CVE-2024-54542
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.…
Safari
11.2 / 15.2+
MEDIUM 5.3
CVE-2025-24747
Missing Authorization vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through <= 3.4.0.
Mitigation only
HIGH 8.8
CVE-2025-24734
Missing Authorization vulnerability in CodeSolz Better Find and Replace real-time-auto-find-and-replace allows Privilege Escalation.This issue affect…
Mitigation only
MEDIUM 5.3
CVE-2025-24662
Missing Authorization vulnerability in LearnDash LearnDash LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…
No fix yet
MEDIUM 5.3
CVE-2025-24600
Missing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through <= 11.4.5.
No fix yet
MEDIUM 6.4
CVE-2025-24606
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access C…
Mitigation only
MEDIUM 5.4
CVE-2025-23849
Missing Authorization vulnerability in bpiwowar PAPERCITE papercite allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…
Mitigation only
HIGH 7.1
CVE-2025-23982
Missing Authorization vulnerability in Gopi krishnan Fare Calculator fare-calculator allows Stored XSS.This issue affects Fare Calculator: from n/a t…
Mitigation only
MEDIUM 5.3
CVE-2025-24590
Missing Authorization vulnerability in picu picu picu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects picu…
Mitigation only