Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-10034 The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.39. This is due to the… Mitigation only Fix from $1,6002026-06-19 MEDIUM 6.5 CVE-2026-52866 An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applicati… Mitigation only Fix from $1,6002026-06-19 MEDIUM 6.5 CVE-2026-49205 phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 add… Patch available Fix from $1,6002026-06-18 HIGH 8.1 CVE-2026-11719 An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handle… Mcp Toolbox For Databases Patch available Fix from $1,9502026-06-18 MEDIUM 5.5 CVE-2026-28573 In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of servic… Android Mitigation only Fix from $1,6002026-06-18 MEDIUM 5.3 CVE-2026-12093 The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plug… Mitigation only Fix from $1,6002026-06-18 MEDIUM 5.3 CVE-2026-10029 The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all… Mitigation only Fix from $1,6002026-06-18 HIGH 8.8 CVE-2026-12407 The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.32.26. This… Mitigation only Fix from $1,9502026-06-18 HIGH 7.5 CVE-2026-54810 Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue a… Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-54415 Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticate… Patch available Fix from $1,9502026-06-17 HIGH 7.3 CVE-2025-69189 Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBa… Mitigation only Fix from $1,9502026-06-17 MEDIUM 5.3 CVE-2026-8383 The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowi… Mitigation only Fix from $1,6002026-06-17 HIGH 7.5 CVE-2026-54802 Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.2 CVE-2026-49081 Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions. Mitigation only Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2026-49072 Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions. Mitigation only Fix from $1,6002026-06-17 HIGH 7.5 CVE-2026-49057 Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions. Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.3 CVE-2026-48797 Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI expo… Mitigation only Fix from $2,3002026-06-17 MEDIUM 6.5 CVE-2026-45436 Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions. Mitigation only Fix from $1,6002026-06-17 MEDIUM 5.5 CVE-2026-40722 Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issu… No fix yet Fix from $1,6002026-06-17 HIGH 8.2 CVE-2026-40726 Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions. Mitigation only Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2026-39433 Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions. Mitigation only Fix from $1,6002026-06-17 MEDIUM 5.5 CVE-2026-28587 In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lea… Android Mitigation only Fix from $1,6002026-06-17 HIGH 7.8 CVE-2026-28615 In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privi… Android Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.1 CVE-2026-24611 Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. Mitigation only Fix from $2,3002026-06-17 HIGH 8.6 CVE-2026-22343 Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.4 CVE-2026-11858 Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The update service runs as NT AUTHORI… Mitigation only Fix from $1,9502026-06-17 HIGH 7.8 CVE-2026-0071 In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with … Android Mitigation only Fix from $1,9502026-06-17 HIGH 7.8 CVE-2026-0081 In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege with no add… Android Mitigation only Fix from $1,9502026-06-17 CRITICAL 10.0 CVE-2026-0092 In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privi… Android Mitigation only Fix from $2,3002026-06-17 MEDIUM 6.5 CVE-2025-69137 Subscriber Broken Access Control in Genemy <= 1.6.6 versions. Mitigation only Fix from $1,6002026-06-17