Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2025-67926 Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security… Mitigation only Fix from $1,6002026-01-08 MEDIUM 6.5 CVE-2025-67913 Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained b… Mitigation only Fix from $1,6002026-01-08 MEDIUM 6.5 CVE-2025-67917 Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… Mitigation only Fix from $1,6002026-01-08 HIGH 7.5 CVE-2025-22715 Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Exp… Mitigation only Fix from $1,9502026-01-08 HIGH 7.5 CVE-2025-14360 Missing Authorization vulnerability in Kaira Blockons blockons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blo… Mitigation only Fix from $1,9502026-01-08 HIGH 7.5 CVE-2025-14358 Missing Authorization vulnerability in sizam REHub Framework rehub-framework allows Accessing Functionality Not Properly Constrained by ACLs.This iss… Mitigation only Fix from $1,9502026-01-08 MEDIUM 6.5 CVE-2025-13679 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… Mitigation only Fix from $1,6002026-01-08 MEDIUM 5.9 CVE-2025-69220 LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file co… Librechat Patch available Fix from $1,6002026-01-07 MEDIUM 6.5 CVE-2025-46434 Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon allows Exploiting Incorrectly Co… Mitigation only Fix from $1,6002026-01-07 HIGH 8.8 CVE-2026-0628EPSS 7% Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicio… Chrome 143.0.7499.192+ Fix from $1,9502026-01-07 HIGH 8.2 CVE-2026-0656 The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2.0.2 v… Mitigation only Fix from $1,9502026-01-07 MEDIUM 6.5 CVE-2025-14901 The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerW… Mitigation only Fix from $1,6002026-01-07 MEDIUM 5.3 CVE-2025-14460 The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modification in all versions up to, and … Mitigation only Fix from $1,6002026-01-07 HIGH 7.5 CVE-2025-14070 The Reviewify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'send_test_email' AJAX… Mitigation only Fix from $1,9502026-01-07 MEDIUM 5.3 CVE-2025-13529 The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'init' action in all versi… Mitigation only Fix from $1,6002026-01-07 MEDIUM 5.3 CVE-2025-13722 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorizatio… Mitigation only Fix from $1,6002026-01-07 HIGH 7.5 CVE-2025-13493 The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, and including, 1.4. This is du… Mitigation only Fix from $1,9502026-01-07 MEDIUM 5.3 CVE-2025-13496 The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the moosend_la… Mitigation only Fix from $1,6002026-01-07 MEDIUM 5.3 CVE-2025-13419 The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unauthorized modification of data du… Mitigation only Fix from $1,6002026-01-07 HIGH 7.5 CVE-2025-11877 The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_… Mitigation only Fix from $1,9502026-01-07 MEDIUM 5.4 CVE-2025-12449 The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive informat… Mitigation only Fix from $1,6002026-01-07 MEDIUM 5.3 CVE-2025-69364 Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… Mitigation only Fix from $1,6002026-01-06 MEDIUM 5.3 CVE-2025-69359 Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This … No fix yet Fix from $1,6002026-01-06 MEDIUM 6.5 CVE-2025-69363 Missing Authorization vulnerability in CyberChimps Responsive Addons for Elementor responsive-addons-for-elementor allows Exploiting Incorrectly Conf… Mitigation only Fix from $1,6002026-01-06 MEDIUM 5.4 CVE-2025-69349 Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Configured Access Control Security… Mitigation only Fix from $1,6002026-01-06 MEDIUM 5.4 CVE-2025-69352 Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Secu… No fix yet Fix from $1,6002026-01-06 MEDIUM 5.4 CVE-2025-69341 Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorre… Mitigation only Fix from $1,6002026-01-06 CRITICAL 9.8 CVE-2025-39477 Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af… Mitigation only Fix from $2,3002026-01-06 MEDIUM 6.5 CVE-2025-9637 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due … Quiz And Survey Master 10.3.2+ Fix from $1,6002026-01-06 MEDIUM 5.3 CVE-2025-13964 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… Mitigation only Fix from $1,6002026-01-06