Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.5 CVE-2025-69103 Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.0 CVE-2025-48640 In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (pro… Android No fix yet Fix from $1,9502026-06-17 HIGH 7.8 CVE-2025-48617 In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local esca… Android Mitigation only Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2024-37210 Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects A… Mitigation only Fix from $1,6002026-06-17 HIGH 8.3 CVE-2024-32949 Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This i… Mitigation only Fix from $1,9502026-06-17 MEDIUM 5.3 CVE-2024-33909 Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue a… No fix yet Fix from $1,6002026-06-17 MEDIUM 6.5 CVE-2026-12105 Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with in… Devolutions Server 2026.1.22.0 / 2026.2.7.0+ Fix from $1,6002026-06-16 HIGH 7.8 CVE-2026-0133 In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check.… Android Mitigation only Fix from $1,9502026-06-16 HIGH 8.1 CVE-2026-53866 OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute u… Openclaw 2026.5.12+ Fix from $1,9502026-06-16 MEDIUM 5.5 CVE-2026-53850 OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute… Openclaw 2026.4.25+ Fix from $1,6002026-06-16 MEDIUM 5.3 CVE-2026-53851 OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled re… Openclaw 2026.5.12+ Fix from $1,6002026-06-16 MEDIUM 6.5 CVE-2026-53844 OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to acces… Openclaw 2026.4.29+ Fix from $1,6002026-06-16 MEDIUM 6.9 CVE-2026-10831 A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The command interface does not prop… Mitigation only Fix from $1,6002026-06-16 HIGH 8.3 CVE-2025-14272 A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized … Mitigation only Fix from $1,9502026-06-16 MEDIUM 5.9 CVE-2026-52714 Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions. Mitigation only Fix from $1,6002026-06-16 MEDIUM 6.5 CVE-2026-54190 Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions. Mitigation only Fix from $1,6002026-06-16 HIGH 7.5 CVE-2026-39490 Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions. Mitigation only Fix from $1,9502026-06-16 MEDIUM 6.5 CVE-2026-40809 Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issu… No fix yet Fix from $1,6002026-06-16 HIGH 7.5 CVE-2026-52711 Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions. Mitigation only Fix from $1,9502026-06-16 MEDIUM 6.5 CVE-2026-2381 The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… Mitigation only Fix from $1,6002026-06-16 HIGH 7.5 CVE-2025-68045 Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions. Mitigation only Fix from $1,9502026-06-16 MEDIUM 5.3 CVE-2026-9187 The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This i… Mitigation only Fix from $1,6002026-06-16 MEDIUM 5.3 CVE-2026-6964 The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due … Mitigation only Fix from $1,6002026-06-16 MEDIUM 6.5 CVE-2026-49775 Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions. Mitigation only Fix from $1,6002026-06-15 HIGH 8.2 CVE-2026-49065 Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.5 CVE-2026-49070 Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions. Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.1 CVE-2026-48881 Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. Mitigation only Fix from $2,3002026-06-15 HIGH 7.5 CVE-2026-48883 Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions. Mitigation only Fix from $1,9502026-06-15 MEDIUM 6.5 CVE-2026-48887 Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions. Mitigation only Fix from $1,6002026-06-15 HIGH 7.5 CVE-2026-48873 Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions. Mitigation only Fix from $1,9502026-06-15