Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2019-25351 Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary system files through the server.… No fix yet Fix from $1,9502026-02-18 MEDIUM 6.5 CVE-2026-1355 A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another u… Enterprise Server 3.14.23 / 3.15.18+ Fix from $1,6002026-02-18 CRITICAL 9.8 CVE-2025-70150 CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attacker… Membership Management System Mitigation only Fix from $2,3002026-02-18 HIGH 7.5 CVE-2025-70148 Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers … Membership Management System No fix yet Fix from $1,9502026-02-18 HIGH 7.5 CVE-2025-70147 Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtai… Online Time Table Generator No fix yet Fix from $1,9502026-02-18 CRITICAL 9.4 CVE-2025-70141 SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authe… Customer Support System No fix yet Fix from $2,3002026-02-18 CRITICAL 9.1 CVE-2025-70146 Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attacke… Online Time Table Generator No fix yet Fix from $2,3002026-02-18 MEDIUM 6.5 CVE-2026-1942 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… Mitigation only Fix from $1,6002026-02-18 MEDIUM 5.3 CVE-2026-1656 The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check in all versions up to, and inc… Mitigation only Fix from $1,6002026-02-18 MEDIUM 5.4 CVE-2026-2127 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all versions up to, and including, … Mitigation only Fix from $1,6002026-02-18 MEDIUM 5.3 CVE-2026-1938 The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized license key deletion due to a missing authorization che… Mitigation only Fix from $1,6002026-02-18 HIGH 7.2 CVE-2026-1937 The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat… Mitigation only Fix from $1,9502026-02-18 MEDIUM 6.5 CVE-2024-31118 Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,6002026-02-17 MEDIUM 6.5 CVE-2022-41650 Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.This issue affects Custom Conten… Mitigation only Fix from $1,6002026-02-17 MEDIUM 6.6 CVE-2026-25903 Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required … Nifi 2.8.0+ Fix from $1,6002026-02-17 MEDIUM 5.8 CVE-2026-0829 The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security chec… Mitigation only Fix from $1,6002026-02-17 MEDIUM 5.3 CVE-2026-1657 The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the… Mitigation only Fix from $1,6002026-02-17 HIGH 8.8 CVE-2026-2001 The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activ… Mitigation only Fix from $1,9502026-02-16 HIGH 8.1 CVE-2026-26367 eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authe… Enet Smart Home No fix yet Fix from $1,9502026-02-15 HIGH 8.8 CVE-2026-26368 eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword JSON-RPC method that allows any authen… Enet Smart Home No fix yet Fix from $1,9502026-02-15 MEDIUM 5.3 CVE-2026-1944 The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cb… Mitigation only Fix from $1,6002026-02-14 MEDIUM 5.3 CVE-2026-1303 The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.2.4. This is due to missi… Mitigation only Fix from $1,6002026-02-14 MEDIUM 5.4 CVE-2026-0727 The Accordion and Accordion Slider plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.5. This is du… Mitigation only Fix from $1,6002026-02-14 MEDIUM 5.3 CVE-2026-1932 The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… Mitigation only Fix from $1,6002026-02-14 HIGH 7.5 CVE-2026-0692 The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0.… Mitigation only Fix from $1,9502026-02-14 MEDIUM 5.3 CVE-2025-14067 The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in… Mitigation only Fix from $1,6002026-02-14 MEDIUM 5.3 CVE-2025-14608 The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.5. This is… Patch available Fix from $1,6002026-02-14 HIGH 8.8 CVE-2025-15157 The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to pri… Mitigation only Fix from $1,9502026-02-13 CRITICAL 9.9 CVE-2026-26268 Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicio… Cursor 2.5+ Fix from $2,3002026-02-13 MEDIUM 6.5 CVE-2026-25768 LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should n… Lavinmq 2.6.6+ Fix from $1,6002026-02-12