Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-23632 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write… Gogs 0.13.4+ Fix from $1,6002026-02-06 HIGH 8.8 CVE-2026-1499 The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1… Mitigation only Fix from $1,9502026-02-06 MEDIUM 5.3 CVE-2025-10753 The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14… Mitigation only Fix from $1,6002026-02-06 HIGH 8.8 CVE-2025-15330 Tanium addressed an improper input validation vulnerability in Deploy. Deploy 2.26.1279 / 2.30.175+ Fix from $1,9502026-02-05 MEDIUM 5.4 CVE-2026-1927 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec… Mitigation only Fix from $1,6002026-02-05 MEDIUM 5.3 CVE-2025-14079 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and includ… Mitigation only Fix from $1,6002026-02-05 HIGH 8.8 CVE-2026-25538 Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists in Devtron's Attributes API in… Devtron 2.0.0+ Fix from $1,9502026-02-04 MEDIUM 5.3 CVE-2026-0679 The Fortis for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an inverted nonce check in the 'check_fortis_notify_resp… Mitigation only Fix from $1,6002026-02-04 MEDIUM 5.3 CVE-2025-15507 The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the … Mitigation only Fix from $1,6002026-02-04 MEDIUM 6.5 CVE-2026-0572 The WebPurify Profanity Filter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'webp… Mitigation only Fix from $1,6002026-02-04 MEDIUM 6.5 CVE-2025-15260 The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization in all versions up to, and inc… Mitigation only Fix from $1,6002026-02-04 HIGH 7.5 CVE-2025-15285 The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the checkBlog… Mitigation only Fix from $1,9502026-02-04 MEDIUM 5.3 CVE-2025-14461 The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, and including, 6.0.2. This is … Mitigation only Fix from $1,6002026-02-04 MEDIUM 5.4 CVE-2026-25028 Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Inco… Mitigation only Fix from $1,6002026-02-03 MEDIUM 6.5 CVE-2026-25036 Missing Authorization vulnerability in WP Chill Passster content-protector allows Exploiting Incorrectly Configured Access Control Security Levels.Th… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.3 CVE-2026-25019 Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.4 CVE-2026-25021 Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control S… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.3 CVE-2026-25010 Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Level… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.3 CVE-2026-25012 Missing Authorization vulnerability in gfazioli WP Bannerize Pro wp-bannerize-pro allows Exploiting Incorrectly Configured Access Control Security Le… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.4 CVE-2026-24990 Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.3 CVE-2026-24994 Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Cont… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.3 CVE-2026-24997 Missing Authorization vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Exploiting Incorrectly… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.3 CVE-2026-24967 Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.3 CVE-2026-24982 Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control… Mitigation only Fix from $1,6002026-02-03 MEDIUM 6.5 CVE-2026-24984 Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Configured Access Control Securit… Mitigation only Fix from $1,6002026-02-03 MEDIUM 6.5 CVE-2026-24957 Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Secur… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.3 CVE-2026-24945 Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly C… Mitigation only Fix from $1,6002026-02-03 HIGH 8.5 CVE-2025-13348 An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered by a local… Mitigation only Fix from $1,9502026-02-02 MEDIUM 5.3 CVE-2026-1734 A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/… Crmeb after 5.6.3 Fix from $1,6002026-02-02 MEDIUM 5.3 CVE-2026-1431 The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTI… Mitigation only Fix from $1,6002026-01-31