Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2026-24055 Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates… Langfuse 3.147.0+ Fix from $1,6002026-01-22 MEDIUM 5.3 CVE-2026-1036 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.3 CVE-2026-23990 The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in… Flux Operator 0.40.0+ Fix from $1,6002026-01-21 HIGH 8.1 CVE-2026-23517 Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowe… Fleet 4.53.3 / 4.75.2+ Fix from $1,9502026-01-21 MEDIUM 5.4 CVE-2026-0548 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized attachment deletion due to a missing capabili… Mitigation only Fix from $1,6002026-01-20 MEDIUM 5.4 CVE-2025-15043 The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel… Mitigation only Fix from $1,6002026-01-20 HIGH 8.8 CVE-2025-15347 The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead t… Mitigation only Fix from $1,9502026-01-20 MEDIUM 5.3 CVE-2025-14351 The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '… Mitigation only Fix from $1,6002026-01-20 MEDIUM 5.3 CVE-2025-14798 The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.2.4 via the… Mitigation only Fix from $1,6002026-01-20 MEDIUM 5.3 CVE-2025-14978 The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for WordPress is vulnerable to una… Mitigation only Fix from $1,6002026-01-20 MEDIUM 5.4 CVE-2025-15466 The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability… Mitigation only Fix from $1,6002026-01-20 MEDIUM 5.4 CVE-2026-23875 CrawlChat is an open-source, AI-powered platform that transforms technical documentation into intelligent chatbots. Prior to version 0.0.8, a non-exi… Crawlchat 0.0.8+ Fix from $1,6002026-01-19 HIGH 8.8 CVE-2026-1169 A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. Such manipulation leads to cr… Prime after 0.4.0 Fix from $1,9502026-01-19 MEDIUM 6.5 CVE-2026-1148 A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This vulnerability affects unknown … Patients Waiting Area Queue Management System Mitigation only Fix from $1,6002026-01-19 MEDIUM 6.5 CVE-2026-1142 A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in … News Portal No fix yet Fix from $1,6002026-01-19 MEDIUM 5.3 CVE-2025-14078 The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.6. This is due to m… Mitigation only Fix from $1,6002026-01-17 MEDIUM 5.3 CVE-2025-14029 The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_admin_even… Mitigation only Fix from $1,6002026-01-17 MEDIUM 5.3 CVE-2025-12825 The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the… Mitigation only Fix from $1,6002026-01-17 MEDIUM 5.3 CVE-2025-14463 The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This … Mitigation only Fix from $1,6002026-01-17 MEDIUM 6.5 CVE-2025-14450 The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'c… Mitigation only Fix from $1,6002026-01-17 MEDIUM 5.3 CVE-2026-1004 The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via… Patch available Fix from $1,6002026-01-16 MEDIUM 5.3 CVE-2025-14757 The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 o… Cost Calculator Builder 3.6.10+ Fix from $1,6002026-01-16 MEDIUM 6.5 CVE-2026-1000 The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deletion in all versions up to, and… Mitigation only Fix from $1,6002026-01-16 MEDIUM 6.5 CVE-2025-12641 The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all… Mitigation only Fix from $1,6002026-01-16 HIGH 8.2 CVE-2025-64729 The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed… Process Optimization 2025+ Fix from $1,9502026-01-16 CRITICAL 9.8 CVE-2021-47812 GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code thro… Grav Mitigation only Fix from $2,3002026-01-16 MEDIUM 6.4 CVE-2025-13859 The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… Mitigation only Fix from $1,6002026-01-15 MEDIUM 5.3 CVE-2025-12895 The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending due to a missing capability che… Mitigation only Fix from $1,6002026-01-15 HIGH 7.4 CVE-2025-14457 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ow… Contact Form 7 after 1.3.9.2 Fix from $1,9502026-01-15 MEDIUM 6.5 CVE-2026-23477 Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1… Rocket.chat 6.12.0+ Fix from $1,6002026-01-14