Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.9 CVE-2026-27344 Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.Th… Mitigation only Fix from $1,6002026-03-05 HIGH 7.5 CVE-2026-27361 Missing Authorization vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows Exploiting Incorrectly Confi… Mitigation only Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-23799 Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… Mitigation only Fix from $1,6002026-03-05 HIGH 7.5 CVE-2026-22479 Missing Authorization vulnerability in ThemeRuby Easy Post Submission easy-post-submission allows Exploiting Incorrectly Configured Access Control Se… Mitigation only Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-22459 Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Configured Access Control Security… Mitigation only Fix from $1,6002026-03-05 HIGH 7.5 CVE-2025-69340 Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorre… Mitigation only Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-2899 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is du… Mitigation only Fix from $1,6002026-03-05 MEDIUM 6.5 CVE-2026-1674 The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to unauthorized… Mitigation only Fix from $1,6002026-03-04 MEDIUM 5.4 CVE-2026-2732 The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBa… Patch available Fix from $1,6002026-03-04 CRITICAL 9.8 CVE-2026-3266 Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF t… Filr 25.1.3+ Fix from $2,3002026-03-03 MEDIUM 5.4 CVE-2025-13734 IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized acces… Engineering Requirements Management Doors Next Mitigation only Fix from $1,6002026-03-03 MEDIUM 5.3 CVE-2026-1336 The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to mi… Mitigation only Fix from $1,6002026-03-03 HIGH 7.8 CVE-2026-0026 In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due to a logic error in the code… Android Mitigation only Fix from $1,9502026-03-02 HIGH 7.3 CVE-2025-48634 In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escala… Android Mitigation only Fix from $1,9502026-03-02 HIGH 8.4 CVE-2025-48574 In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission che… Android Mitigation only Fix from $1,9502026-03-02 HIGH 7.8 CVE-2025-48578 In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permission chec… Android Mitigation only Fix from $1,9502026-03-02 CRITICAL 9.8 CVE-2026-3431 On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or hos… Sim 0.5.74+ Fix from $2,3002026-03-02 CRITICAL 9.1 CVE-2026-3432 On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided … Sim 0.5.74+ Fix from $2,3002026-03-02 MEDIUM 5.4 CVE-2026-28556 wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split any forum topic via… Wpforo Forum 2.4.16+ Fix from $1,6002026-02-28 MEDIUM 6.5 CVE-2026-28557 wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment v… Wpforo Forum 2.4.16+ Fix from $1,6002026-02-28 MEDIUM 6.5 CVE-2026-28424 Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in re… Statamic 5.73.11 / 6.4.0+ Fix from $1,6002026-02-27 HIGH 8.8 CVE-2026-28515 openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The install… Opendcim Patch available Fix from $1,9502026-02-27 CRITICAL 9.8 CVE-2026-28408 WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the pr… Wegia 3.6.5+ Fix from $2,3002026-02-27 HIGH 7.5 CVE-2026-27836 phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active u… Phpmyfaq 4.0.18+ Fix from $1,9502026-02-27 MEDIUM 5.4 CVE-2026-27792 Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified i… Seerr 3.1.0+ Fix from $1,6002026-02-27 HIGH 7.5 CVE-2026-28276 Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded… Initiative 0.32.2+ Fix from $1,9502026-02-26 MEDIUM 6.5 CVE-2026-28217 hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection… Hoppscotch 2026.2.0+ Fix from $1,6002026-02-26 HIGH 7.1 CVE-2026-27638 Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify … Actual 26.2.1+ Fix from $1,9502026-02-26 MEDIUM 5.3 CVE-2026-27021 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoint in the poll plugin lacked p… Discourse 2025.12.0 / 2026.1.1+ Fix from $1,6002026-02-26 MEDIUM 5.4 CVE-2026-26207 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy` plugin allows any authentica… Discourse 2025.12.0 / 2026.1.1+ Fix from $1,6002026-02-26