Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-39509 Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-39520 Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-39501 Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security … Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-39504 Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Level… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-39505 Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured … Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-39488 Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue … Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-3477 The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. The pzfm_user_request_… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-3480 The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. The plugin registers an admin… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-3646 The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all ver… Mitigation only Fix from $1,6002026-04-08 CRITICAL 9.8 CVE-2026-4003 The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including … Mitigation only Fix from $2,3002026-04-08 MEDIUM 5.3 CVE-2026-4299 The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a miss… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-2263 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-4065 The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp… Mitigation only Fix from $1,6002026-04-07 CRITICAL 9.8 CVE-2026-39397 @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers… Payload Puck 0.6.23+ Fix from $2,3002026-04-07 MEDIUM 5.4 CVE-2026-39401 Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event… Cronicle 0.9.111+ Fix from $1,6002026-04-07 CRITICAL 9.1 CVE-2026-39351 Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit. Frappe 15.104.0 / 16.14.0+ Fix from $2,3002026-04-07 HIGH 8.8 CVE-2026-39355 Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any au… Genealogy 5.9.1+ Fix from $1,9502026-04-07 MEDIUM 5.3 CVE-2026-22680 OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to … Openviking 0.3.3+ Fix from $1,6002026-04-07 HIGH 7.5 CVE-2026-35606 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Filebrowser after 2.63.0 Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-22683 Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited… Flow after 1.614.0 Fix from $1,9502026-04-07 MEDIUM 5.3 CVE-2025-14944 The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missin… Mitigation only Fix from $1,6002026-04-07 CRITICAL 9.8 CVE-2026-4277 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated o… Django 4.2.30 / 5.2.13+ Fix from $2,3002026-04-07 MEDIUM 5.3 CVE-2026-34899 Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Acc… Mitigation only Fix from $1,6002026-04-07 MEDIUM 5.4 CVE-2026-34903 Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… Mitigation only Fix from $1,6002026-04-07 MEDIUM 5.3 CVE-2026-35179 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoin… Avideo after 26.0 Fix from $1,6002026-04-06 HIGH 8.8 CVE-2026-35182 Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.… Bravecms 2.0.6+ Fix from $1,9502026-04-06 MEDIUM 6.5 CVE-2026-35175 Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) coul… Ajenti 2.2.15+ Fix from $1,6002026-04-06 CRITICAL 10.0 CVE-2026-34976 Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware… Dgraph after 25.3.0 Fix from $2,3002026-04-06 HIGH 7.8 CVE-2024-14032 Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to exe… Twitch Studio after 0.114.8 Fix from $1,9502026-04-06 HIGH 8.8 CVE-2026-3524 Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authent… Legal Hold 1.1.5+ Fix from $1,9502026-04-06