Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-3098 The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll'… Mitigation only Fix from $1,6002026-03-27 HIGH 8.1 CVE-2026-29070 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an access control check is… Open Webui 0.8.6+ Fix from $1,9502026-03-27 MEDIUM 5.3 CVE-2026-33638 Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/allusers` is mounted as a public… Ech0 4.2.0+ Fix from $1,6002026-03-26 HIGH 8.7 CVE-2026-33631 ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the o… Clearancekit 4.2+ Fix from $1,9502026-03-26 HIGH 7.8 CVE-2026-33632 ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.4, two file operation event… Clearancekit 4.2.4+ Fix from $1,9502026-03-26 MEDIUM 6.5 CVE-2026-33495 ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Ory O… Oathkeeper 26.2.0+ Fix from $1,6002026-03-26 HIGH 8.8 CVE-2026-33413 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypas… Etcd 3.4.42 / 3.5.28+ Fix from $1,9502026-03-26 MEDIUM 5.3 CVE-2026-4281 The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. Thi… Mitigation only Fix from $1,6002026-03-26 HIGH 8.8 CVE-2026-4484 The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin a… Mitigation only Fix from $1,9502026-03-26 HIGH 8.1 CVE-2026-34053 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorizat… Openemr 8.0.0.3+ Fix from $1,9502026-03-26 MEDIUM 5.4 CVE-2026-33915 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance com… Openemr 8.0.0.3+ Fix from $1,6002026-03-26 HIGH 8.8 CVE-2026-33918 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-d… Openemr 8.0.0.3+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-32546 Missing Authorization vulnerability in StellarWP Restrict Content restrict-content allows Exploiting Incorrectly Configured Access Control Security L… Mitigation only Fix from $1,9502026-03-25 MEDIUM 5.4 CVE-2026-32562 Missing Authorization vulnerability in WP Folio Team PPWP password-protect-page allows Exploiting Incorrectly Configured Access Control Security Leve… Mitigation only Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2026-32541 Missing Authorization vulnerability in Premmerce Premmerce Redirect Manager premmerce-redirect-manager allows Exploiting Incorrectly Configured Acces… Mitigation only Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2026-32527 Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows… Mitigation only Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2026-32514 Missing Authorization vulnerability in Anton Voytenko Petitioner petitioner allows Exploiting Incorrectly Configured Access Control Security Levels.T… No fix yet Fix from $1,6002026-03-25 HIGH 7.5 CVE-2026-32515 Missing Authorization vulnerability in kamleshyadav Miraculous miraculous allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… Mitigation only Fix from $1,9502026-03-25 HIGH 7.1 CVE-2026-32501 Missing Authorization vulnerability in wp-configurator WP Configurator Pro wp-configurator-pro allows Exploiting Incorrectly Configured Access Contro… Mitigation only Fix from $1,9502026-03-25 HIGH 7.5 CVE-2026-32495 Missing Authorization vulnerability in Link Software LLC WP Terms Popup wp-terms-popup allows Exploiting Incorrectly Configured Access Control Securi… Mitigation only Fix from $1,9502026-03-25 HIGH 7.5 CVE-2026-32498 Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorre… Mitigation only Fix from $1,9502026-03-25 HIGH 7.7 CVE-2026-32441 Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured… Mitigation only Fix from $1,9502026-03-25 MEDIUM 6.5 CVE-2026-32483 Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Se… Mitigation only Fix from $1,6002026-03-25 HIGH 7.5 CVE-2026-32485 Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Leve… Mitigation only Fix from $1,9502026-03-25 MEDIUM 6.5 CVE-2026-32489 Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue … No fix yet Fix from $1,6002026-03-25 HIGH 8.2 CVE-2026-31921 Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorre… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.1 CVE-2026-27071 Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af… Mitigation only Fix from $2,3002026-03-25 MEDIUM 6.5 CVE-2026-27046 Missing Authorization vulnerability in Kaira StoreCustomizer woocustomizer allows Exploiting Incorrectly Configured Access Control Security Levels.Th… Mitigation only Fix from $1,6002026-03-25 MEDIUM 6.3 CVE-2026-25460 Missing Authorization vulnerability in LiquidThemes Ave Core ave-core allows Exploiting Incorrectly Configured Access Control Security Levels.This is… Mitigation only Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2026-25462 Missing Authorization vulnerability in avalex avalex avalex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect… Mitigation only Fix from $1,6002026-03-25