Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.4 CVE-2026-44315 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAu… Free5gc 4.2.2+ Fix from $2,3002026-05-27 HIGH 8.2 CVE-2026-42083 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows un… Free5gc 4.2.2+ Fix from $1,9502026-05-27 MEDIUM 5.3 CVE-2026-49053 Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Level… Mitigation only Fix from $1,6002026-05-27 HIGH 7.3 CVE-2026-31266 Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate). Mitigation only Fix from $1,9502026-05-27 HIGH 7.3 CVE-2026-42753 Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Se… Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-42726 Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured … Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-3897 The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.5 CVE-2026-3279 The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `do… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-3895 The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action … Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-3896 The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versio… Mitigation only Fix from $1,6002026-05-27 MEDIUM 5.3 CVE-2026-9014 The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_stats() functi… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.5 CVE-2026-9603 A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/dele… No fix yet Fix from $1,6002026-05-26 MEDIUM 5.3 CVE-2026-48592 Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthorized job worker substitution.… Patch available Fix from $1,6002026-05-26 MEDIUM 5.3 CVE-2026-42337 MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file se… Mitigation only Fix from $1,6002026-05-26 HIGH 7.1 CVE-2025-14361 Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This i… Mitigation only Fix from $1,9502026-05-26 MEDIUM 6.3 CVE-2026-27331 Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issu… Mitigation only Fix from $1,6002026-05-26 MEDIUM 5.3 CVE-2026-25426 Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control S… Mitigation only Fix from $1,6002026-05-26 HIGH 7.8 CVE-2026-24190 NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resour… Gpu Display Driver 535.309.01 / 539.72+ Fix from $1,9502026-05-26 MEDIUM 5.3 CVE-2026-24590 Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security … Mitigation only Fix from $1,6002026-05-26 MEDIUM 5.3 CVE-2026-39655 Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue… Mitigation only Fix from $1,6002026-05-26 MEDIUM 6.5 CVE-2026-4795 A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)… Mitigation only Fix from $1,6002026-05-26 MEDIUM 6.3 CVE-2026-42776 Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This… Mitigation only Fix from $1,6002026-05-25 HIGH 7.5 CVE-2026-45209 Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. Th… Mitigation only Fix from $1,9502026-05-25 HIGH 7.5 CVE-2026-45438 Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Level… Mitigation only Fix from $1,9502026-05-25 MEDIUM 5.4 CVE-2026-32389 Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affec… No fix yet Fix from $1,6002026-05-25 MEDIUM 6.5 CVE-2026-42763 Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue affects SePay Gateway: from n/a … Mitigation only Fix from $1,6002026-05-25 MEDIUM 5.4 CVE-2026-24586 Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects… No fix yet Fix from $1,6002026-05-25 MEDIUM 5.3 CVE-2026-24592 Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. … Mitigation only Fix from $1,6002026-05-25 MEDIUM 5.3 CVE-2026-27357 Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels. This… Mitigation only Fix from $1,6002026-05-25 MEDIUM 5.3 CVE-2026-27398 Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. T… Mitigation only Fix from $1,6002026-05-25