Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-15475 The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validat… Mitigation only Fix from $1,6002026-01-14 MEDIUM 5.3 CVE-2025-15512 The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_suc… Mitigation only Fix from $1,6002026-01-14 MEDIUM 5.3 CVE-2025-14173 The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. This is due to missin… Mitigation only Fix from $1,6002026-01-14 MEDIUM 5.4 CVE-2025-14854 The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcrm_get_email_recipients and wp… Mitigation only Fix from $1,6002026-01-14 MEDIUM 5.3 CVE-2025-14880 The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … Mitigation only Fix from $1,6002026-01-14 HIGH 8.1 CVE-2025-11669 Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnera… Manageengine Pam360 4.4 / 8.2+ Fix from $1,9502026-01-13 MEDIUM 6.4 CVE-2025-59021 Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect r… TYPO3 10.4.55 / 11.5.49+ Fix from $1,6002026-01-13 HIGH 8.1 CVE-2025-59022 Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether th… TYPO3 10.4.55 / 11.5.49+ Fix from $1,9502026-01-13 MEDIUM 5.4 CVE-2025-14001 The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'duplicateBulkH… Mitigation only Fix from $1,6002026-01-13 HIGH 8.1 CVE-2026-0506 Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC functi… Netweaver Application Server Abap Patch available Fix from $1,9502026-01-13 HIGH 8.1 CVE-2026-0511 SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation … Mitigation only Fix from $1,9502026-01-13 MEDIUM 6.4 CVE-2026-0503 Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcod… Mitigation only Fix from $1,6002026-01-13 MEDIUM 5.3 CVE-2025-14948 The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a… Mitigation only Fix from $1,6002026-01-10 MEDIUM 5.3 CVE-2026-0817 Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki … Campaignevents Patch available Fix from $1,6002026-01-09 MEDIUM 6.5 CVE-2025-14172 The WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.4. This is due … Mitigation only Fix from $1,6002026-01-09 MEDIUM 5.3 CVE-2025-13717 The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_gvccf… Mitigation only Fix from $1,6002026-01-09 MEDIUM 6.5 CVE-2025-13781 GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could hav… GitLab 18.5.5 / 18.6.3+ Fix from $1,6002026-01-09 MEDIUM 5.3 CVE-2025-14146 The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPB… Mitigation only Fix from $1,6002026-01-09 HIGH 7.2 CVE-2025-14657 The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data… Mitigation only Fix from $1,9502026-01-09 CRITICAL 9.1 CVE-2025-14741 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a … Mitigation only Fix from $2,3002026-01-09 MEDIUM 5.3 CVE-2025-14720 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks … Mitigation only Fix from $1,6002026-01-09 MEDIUM 5.3 CVE-2025-14782 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up… Mitigation only Fix from $1,6002026-01-09 MEDIUM 5.4 CVE-2025-14718 The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4… Mitigation only Fix from $1,6002026-01-09 MEDIUM 5.3 CVE-2025-14886 The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `order… Mitigation only Fix from $1,6002026-01-09 MEDIUM 6.5 CVE-2026-22522 Missing Authorization vulnerability in Munir Kamal Block Slider block-slider allows Exploiting Incorrectly Configured Access Control Security Levels.… Mitigation only Fix from $1,6002026-01-08 MEDIUM 5.3 CVE-2026-22488 Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beaver-builder allows Exploiting … Mitigation only Fix from $1,6002026-01-08 MEDIUM 5.4 CVE-2026-22490 Missing Authorization vulnerability in niklaslindemann Bulk Landing Page Creator for WordPress LPagery lpagery allows Exploiting Incorrectly Configur… Mitigation only Fix from $1,6002026-01-08 MEDIUM 5.4 CVE-2026-22517 Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Acc… Mitigation only Fix from $1,6002026-01-08 MEDIUM 5.3 CVE-2026-22486 Missing Authorization vulnerability in Re Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Re Galle… No fix yet Fix from $1,6002026-01-08 MEDIUM 5.3 CVE-2026-0676 Missing Authorization vulnerability in G5Theme Zorka zorka allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… No fix yet Fix from $1,6002026-01-08