Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.5 CVE-2026-61954 Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions. No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-61972 Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions. No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-59547 Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. No fix yet Fix from $1,9502026-07-23 HIGH 7.5 CVE-2026-61943 Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. No fix yet Fix from $1,9502026-07-23 MEDIUM 6.5 CVE-2026-59522 Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-57808 Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.3 CVE-2026-57703 Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-57717 Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-57425 Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions. No fix yet Fix from $1,6002026-07-23 HIGH 7.1 CVE-2026-57367 Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. No fix yet Fix from $1,9502026-07-23 MEDIUM 6.7 CVE-2026-27377 Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-27391 Subscriber Broken Access Control in uListing <= 2.2.0 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-27399 Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-27418 Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-27422 Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-27355 Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-25427 Subscriber Broken Access Control in eRoom <= 1.7.1 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-25466 Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-15827 The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/m… No fix yet Fix from $1,6002026-07-23 CRITICAL 9.8 CVE-2026-15015 The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. T… Mitigation only Fix from $2,3002026-07-23 MEDIUM 6.8 CVE-2026-59677 A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-own… No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-12082 The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated us… No fix yet Fix from $1,9502026-07-23 HIGH 7.7 CVE-2026-13078 A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that e… MongoDB No fix yet Fix from $1,9502026-07-22 MEDIUM 6.8 CVE-2026-7328 Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode… No fix yet Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-16544 A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access… No fix yet Fix from $1,6002026-07-22 MEDIUM 5.4 CVE-2026-63141 Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without … Kibana 9.3.8 / 9.4.4+ Fix from $1,6002026-07-21 HIGH 7.3 CVE-2026-61267 Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that… Human Capital Management Configuration Workbench No fix yet Fix from $1,9502026-07-21 HIGH 8.1 CVE-2026-60953 Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported ver… Telecommunications Billing Integrator after 12.2.15 Fix from $1,9502026-07-21 MEDIUM 6.5 CVE-2026-60712 Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affec… Siebel Crm after 26.5 Fix from $1,6002026-07-21 MEDIUM 5.3 CVE-2026-65055 Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal wor… No fix yet Fix from $1,6002026-07-21