Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-35061 Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication, revealing sensitive operatio… Cx7 Firmware Mitigation only Fix from $1,6002026-04-17 MEDIUM 5.3 CVE-2026-32648 Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/RTTY status), assisting attack… Cx7 Firmware Mitigation only Fix from $1,6002026-04-17 MEDIUM 5.3 CVE-2026-33093 Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing camera, exposing visual inform… Cx7 Firmware Mitigation only Fix from $1,6002026-04-17 MEDIUM 5.3 CVE-2026-5502 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to… Mitigation only Fix from $1,6002026-04-17 MEDIUM 5.3 CVE-2026-5427 The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability c… Mitigation only Fix from $1,6002026-04-17 MEDIUM 6.5 CVE-2026-4666 The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-c… Mitigation only Fix from $1,6002026-04-17 MEDIUM 6.5 CVE-2026-3488 The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing c… Mitigation only Fix from $1,6002026-04-17 MEDIUM 5.9 CVE-2026-40265 Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/notes/{noteID}/assets/{assetID… Patch available Fix from $1,6002026-04-17 MEDIUM 5.3 CVE-2026-0718 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized modification of data due… Mitigation only Fix from $1,6002026-04-16 HIGH 8.8 CVE-2026-3614 The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and including, 10.8.1 due to a missing c… Mitigation only Fix from $1,9502026-04-16 CRITICAL 9.8 CVE-2026-3596 The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin regis… Mitigation only Fix from $2,3002026-04-16 MEDIUM 5.3 CVE-2026-3595 The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to t… Mitigation only Fix from $1,6002026-04-16 MEDIUM 5.3 CVE-2026-3581 The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to … Mitigation only Fix from $1,6002026-04-16 HIGH 8.8 CVE-2026-40502 OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive … Openharness 2026-04-13+ Fix from $1,9502026-04-16 HIGH 7.5 CVE-2026-6372 Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configured Access Control Security Le… Mitigation only Fix from $1,9502026-04-15 CRITICAL 9.3 CVE-2026-5387 The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator D… Mitigation only Fix from $2,3002026-04-15 MEDIUM 5.4 CVE-2026-40740 Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… Mitigation only Fix from $1,6002026-04-15 MEDIUM 5.3 CVE-2026-40742 Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Configured Access Control Secur… No fix yet Fix from $1,6002026-04-15 MEDIUM 5.3 CVE-2026-40763 Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control… Mitigation only Fix from $1,6002026-04-15 MEDIUM 5.3 CVE-2026-40778 Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Sec… Mitigation only Fix from $1,6002026-04-15 MEDIUM 5.3 CVE-2026-40730 Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access C… No fix yet Fix from $1,6002026-04-15 MEDIUM 5.3 CVE-2026-3642 The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builde… Mitigation only Fix from $1,6002026-04-15 MEDIUM 5.3 CVE-2026-3649 The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.0. The katalogportal_p… Mitigation only Fix from $1,6002026-04-15 MEDIUM 5.3 CVE-2026-4812 The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and … Mitigation only Fix from $1,6002026-04-15 MEDIUM 5.3 CVE-2026-1314 The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to … Mitigation only Fix from $1,6002026-04-15 CRITICAL 9.1 CVE-2026-35033 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpe… Jellyfin 10.11.7+ Fix from $2,3002026-04-14 MEDIUM 5.3 CVE-2025-15565 The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in… Mitigation only Fix from $1,6002026-04-14 HIGH 8.1 CVE-2026-23708 A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.… Fortisoar 7.5.3 / 7.6.4+ Fix from $1,9502026-04-14 CRITICAL 9.1 CVE-2026-4365 The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` f… Mitigation only Fix from $2,3002026-04-14 HIGH 7.1 CVE-2026-34256 Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular … Mitigation only Fix from $1,9502026-04-14