Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2026-1104 The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missi… Mitigation only Fix from $1,9502026-02-12 MEDIUM 6.5 CVE-2026-1671 The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the winter_acti… Mitigation only Fix from $1,6002026-02-12 MEDIUM 5.3 CVE-2026-1537 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missin… Mitigation only Fix from $1,6002026-02-12 HIGH 7.8 CVE-2026-20626 This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3… Ipados 15.7.4 / 26.3+ Fix from $1,9502026-02-11 MEDIUM 5.8 CVE-2025-13391 The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to unauthorized loss of dat… Mitigation only Fix from $1,6002026-02-11 MEDIUM 5.3 CVE-2025-14592 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under… GitLab 18.6.6 / 18.7.4+ Fix from $1,6002026-02-11 MEDIUM 5.3 CVE-2026-1833 The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0.1. This i… Mitigation only Fix from $1,6002026-02-11 MEDIUM 6.5 CVE-2026-1786 The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dg_tw_opt… Mitigation only Fix from $1,6002026-02-11 MEDIUM 6.5 CVE-2025-15400 The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configur… Mitigation only Fix from $1,6002026-02-11 HIGH 7.2 CVE-2026-21743 A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4… Fortiauthenticator 6.6.7+ Fix from $1,9502026-02-10 MEDIUM 5.4 CVE-2025-14895 The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. This is due to the plugin not pr… Mitigation only Fix from $1,6002026-02-10 MEDIUM 5.3 CVE-2026-1722 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions… Mitigation only Fix from $1,6002026-02-10 HIGH 7.7 CVE-2026-24322 SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allow… Solution Tools Plug In Mitigation only Fix from $1,9502026-02-10 MEDIUM 5.2 CVE-2026-24312 An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restric… Sap Basis Mitigation only Fix from $1,6002026-02-10 CRITICAL 9.6 CVE-2026-0509 SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls with… Netweaver As Abap Kernel Mitigation only Fix from $2,3002026-02-10 CRITICAL 9.9 CVE-2026-0488 An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz… Netweaver Application Server Abap Mitigation only Fix from $2,3002026-02-10 HIGH 7.5 CVE-2026-0490 SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authen… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-0484 Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa… Sap Basis Mitigation only Fix from $1,6002026-02-10 HIGH 7.2 CVE-2026-0845 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized m… Mitigation only Fix from $1,9502026-02-10 CRITICAL 9.1 CVE-2026-25939EPSS 11% FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability i… Fuxa 1.2.11+ Fix from $2,3002026-02-09 HIGH 7.5 CVE-2026-25808 Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security … Hollo 0.6.20 / 0.7.2+ Fix from $1,9502026-02-09 CRITICAL 9.1 CVE-2026-25810 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts… Placipy Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.1 CVE-2026-25876 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify aut… Placipy Mitigation only Fix from $2,3002026-02-09 MEDIUM 6.5 CVE-2026-25806 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/:email PUT /api/students/:ema… Placipy Mitigation only Fix from $1,6002026-02-09 MEDIUM 6.7 CVE-2026-24777 OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permission can lock and unlock use… Openproject 17.0.2+ Fix from $1,6002026-02-09 MEDIUM 5.3 CVE-2026-24095 Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" pe… Mitigation only Fix from $1,6002026-02-09 MEDIUM 6.5 CVE-2026-2208 A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the compo… Wekan 8.21+ Fix from $1,6002026-02-08 HIGH 8.8 CVE-2026-2065 A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Blu… Smart Pixelator Firmware No fix yet Fix from $1,9502026-02-06 CRITICAL 9.1 CVE-2026-25752 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, re… Fuxa 1.2.10+ Fix from $2,3002026-02-06 MEDIUM 6.5 CVE-2026-22592 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files i… Gogs 0.13.4+ Fix from $1,6002026-02-06