Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-21498 Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0… HTTP Server Mitigation only Fix from $1,6002025-01-21 MEDIUM 6.5 CVE-2025-24461 In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint Teamcity Mitigation only Fix from $1,6002025-01-21 HIGH 8.2 CVE-2025-23477 Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Functionality Not Properly Constraine… Mitigation only Fix from $1,9502025-01-21 HIGH 7.5 CVE-2025-22717 Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Accessing Functionality Not Properly Constrained by ACLs.This issue af… Mitigation only Fix from $1,9502025-01-21 HIGH 7.5 CVE-2025-22318 Missing Authorization vulnerability in enituretechnology Standard Box Sizes – for WooCommerce standard-box-sizes.This issue affects Standard Box Size… Mitigation only Fix from $1,9502025-01-21 HIGH 7.5 CVE-2024-12104 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a mis… Atarim 4.1.0+ Fix from $1,9502025-01-21 MEDIUM 5.3 CVE-2024-12071 The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of da… Evergreen Content Poster 1.4.5+ Fix from $1,6002025-01-18 MEDIUM 5.5 CVE-2018-9406 In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privi… Android Mitigation only Fix from $1,6002025-01-18 HIGH 7.8 CVE-2018-9382 In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission… Android Mitigation only Fix from $1,9502025-01-17 MEDIUM 6.5 CVE-2024-50967 The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely acc… Mitigation only Fix from $1,6002025-01-17 MEDIUM 5.3 CVE-2024-12370 The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in a… Wp Hotel Booking 2.1.6+ Fix from $1,6002025-01-17 MEDIUM 6.5 CVE-2024-13367 The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_download action in all versions… Mitigation only Fix from $1,6002025-01-17 HIGH 8.1 CVE-2024-46450 Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication v… Ac6 Firmware Mitigation only Fix from $1,9502025-01-16 MEDIUM 5.4 CVE-2025-23961 Missing Authorization vulnerability in wptasker WordPress Graphs & Charts graph-lite allows Exploiting Incorrectly Configured Access Control Security… Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.4 CVE-2025-23963 Missing Authorization vulnerability in flymke Mark Posts mark-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.4 CVE-2025-23916 Missing Authorization vulnerability in Nuanced Media WP Meetup wp-meetup allows Exploiting Incorrectly Configured Access Control Security Levels.This… Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.4 CVE-2025-23917 Missing Authorization vulnerability in Chandrika Guntur, Morgan Kay Chamber Dashboard Business Directory allows Exploiting Incorrectly Configured Acc… Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.3 CVE-2025-23862 Missing Authorization vulnerability in SzMake Contact Form 7 Anti Spambot contact-form-7-anti-spambot allows Exploiting Incorrectly Configured Access… Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.4 CVE-2025-23778 Missing Authorization vulnerability in Pravin Durugkar User Sync ActiveCampaign registered-user-sync-activecampaign allows Exploiting Incorrectly Con… Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.4 CVE-2025-23761 Missing Authorization vulnerability in Alex Volkov Woo Tuner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affe… Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.3 CVE-2025-23764 Missing Authorization vulnerability in ujjavaljani Copy Move Posts copy-move-posts.This issue affects Copy Move Posts: from n/a through <= 1.6. No fix yet Fix from $1,6002025-01-16 MEDIUM 5.3 CVE-2025-23514 Missing Authorization vulnerability in Sanjay Prasad Loginplus loginplus allows Accessing Functionality Not Properly Constrained by ACLs.This issue a… Mitigation only Fix from $1,6002025-01-16 MEDIUM 6.5 CVE-2024-57682 An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to a… Dir 816 Firmware Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.3 CVE-2024-12427 The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJ… Multi Step Form 1.7.24+ Fix from $1,6002025-01-16 CRITICAL 9.9 CVE-2024-57726 KEVEPSS 67% SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive per… Simplehelp 5.5.8+ Fix from $2,3002025-01-15 HIGH 8.8 CVE-2025-22787 Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue … Button Block 1.1.6+ Fix from $1,9502025-01-15 MEDIUM 5.3 CVE-2025-22737 Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Accessing Functionality Not Properly Constrained by ACLs… Mitigation only Fix from $1,6002025-01-15 MEDIUM 6.5 CVE-2024-56295 Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… Poll Maker 5.5.7+ Fix from $1,6002025-01-15 HIGH 8.1 CVE-2024-11848 The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_not… Mitigation only Fix from $1,9502025-01-15 HIGH 7.5 CVE-2024-57757 JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava. Jeewms 2025.01.01+ Fix from $1,9502025-01-15