Vulnerability index

Browse CVEs

6,896 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-66105 Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Contr… Mitigation only Fix from $1,6002026-05-07 MEDIUM 5.3 CVE-2026-25436 Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This … Mitigation only Fix from $1,6002026-05-07 MEDIUM 6.5 CVE-2026-6214 The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_fo… Mitigation only Fix from $1,6002026-05-07 MEDIUM 6.5 CVE-2026-41658 Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces authorization for destructive opera… Mitigation only Fix from $1,6002026-05-07 MEDIUM 6.5 CVE-2026-4807 The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to… No fix yet Fix from $1,6002026-05-07 MEDIUM 5.3 CVE-2026-6222 The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processR… Mitigation only Fix from $1,6002026-05-07 MEDIUM 6.5 CVE-2026-43583 OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media replay. Attackers can exploit r… Openclaw 2026.4.14+ Fix from $1,6002026-05-06 CRITICAL 9.8 CVE-2026-43575 OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactiv… Openclaw 2026.4.10+ Fix from $2,3002026-05-06 MEDIUM 6.5 CVE-2026-43577 OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through browser act/evaluate interactions.… Openclaw 2026.4.9+ Fix from $1,6002026-05-06 MEDIUM 6.5 CVE-2026-43579 OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that allows operators with write … Openclaw 2026.4.10+ Fix from $1,6002026-05-06 HIGH 7.7 CVE-2026-43580 OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF pol… Openclaw 2026.4.10+ Fix from $1,9502026-05-06 MEDIUM 6.5 CVE-2026-5753 The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. T… Mitigation only Fix from $1,6002026-05-06 MEDIUM 5.3 CVE-2026-3208 The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the … Mitigation only Fix from $1,6002026-05-06 MEDIUM 5.3 CVE-2026-33420 Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organ… Vaultwarden 1.35.5+ Fix from $1,6002026-05-05 MEDIUM 5.3 CVE-2026-43572 OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to ap… Openclaw 2026.4.14+ Fix from $1,6002026-05-05 HIGH 7.7 CVE-2026-43573 OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attacker… Openclaw 2026.4.10+ Fix from $1,9502026-05-05 MEDIUM 6.5 CVE-2026-43567 OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesyst… Openclaw 2026.4.10+ Fix from $1,6002026-05-05 MEDIUM 6.5 CVE-2026-43568 OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory … Openclaw 2026.4.10+ Fix from $1,6002026-05-05 HIGH 7.7 CVE-2026-42436 OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab routes that fail to consistently… Patch available Fix from $1,9502026-05-05 HIGH 8.5 CVE-2026-42439 OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Atta… Openclaw 2026.4.10+ Fix from $1,9502026-05-05 MEDIUM 6.5 CVE-2026-42433 OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persiste… Patch available Fix from $1,6002026-05-05 MEDIUM 6.5 CVE-2026-4362 The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `Li… Mitigation only Fix from $1,6002026-05-05 CRITICAL 9.8 CVE-2026-5294 The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route… Mitigation only Fix from $2,3002026-05-05 HIGH 7.5 CVE-2026-42226 n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify wheth… N8n 1.123.33 / 2.17.5+ Fix from $1,9502026-05-04 MEDIUM 6.5 CVE-2026-42228 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Tri… N8n 1.123.32 / 2.17.4+ Fix from $1,6002026-05-04 CRITICAL 9.9 CVE-2026-42809 Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val… Polaris 1.4.1+ Fix from $2,3002026-05-04 HIGH 7.1 CVE-2026-4100 The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versio… Patch available Fix from $1,9502026-05-02 MEDIUM 5.3 CVE-2026-4024 The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_… Mitigation only Fix from $1,6002026-05-02 MEDIUM 5.3 CVE-2026-4650 The FundPress – WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and including 2.0.8. This is due to m… Mitigation only Fix from $1,6002026-05-02 HIGH 8.8 CVE-2026-6963 The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX … Mitigation only Fix from $1,9502026-05-02