Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-14365 The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to… Mitigation only Fix from $1,6002025-12-13 MEDIUM 5.3 CVE-2025-14366 The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to… Mitigation only Fix from $1,6002025-12-13 MEDIUM 5.3 CVE-2025-14367 The Easy Theme Options plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0. This is due to missing … Mitigation only Fix from $1,6002025-12-13 MEDIUM 5.3 CVE-2025-13093 The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… Mitigation only Fix from $1,6002025-12-13 MEDIUM 5.3 CVE-2025-12362 The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorizatio… Mitigation only Fix from $1,6002025-12-13 MEDIUM 5.3 CVE-2025-13092 The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized access of data due to a missing cap… Mitigation only Fix from $1,6002025-12-13 MEDIUM 5.2 CVE-2025-43497 An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to break out of its s… macOS 26.1+ Fix from $1,6002025-12-12 MEDIUM 5.3 CVE-2025-12655 The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up… Mitigation only Fix from $1,6002025-12-12 MEDIUM 5.4 CVE-2025-14064 The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple AJAX e… Mitigation only Fix from $1,6002025-12-12 MEDIUM 6.4 CVE-2025-13866 The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flo… Mitigation only Fix from $1,6002025-12-12 HIGH 8.1 CVE-2025-13334 The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the… Mitigation only Fix from $1,9502025-12-12 MEDIUM 5.3 CVE-2025-13440 The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This… Mitigation only Fix from $1,6002025-12-12 CRITICAL 9.8 CVE-2025-12963 The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via a… Mitigation only Fix from $2,3002025-12-12 MEDIUM 5.3 CVE-2025-13314 The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for WordPress is vulnerable to unauthorized modification … Mitigation only Fix from $1,6002025-12-12 CRITICAL 9.8 CVE-2020-36902 UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulatin… Medivision Digital Signage Firmware Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2023-53740 Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current… Sft Dab 015\/c Firmware Mitigation only Fix from $2,3002025-12-10 HIGH 8.8 CVE-2021-47701 OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability i… Openbmcs No fix yet Fix from $1,9502025-12-09 MEDIUM 5.4 CVE-2023-23729 Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2022-46845 Missing Authorization vulnerability in Essential Plugin Slider a SlidersPack allows Exploiting Incorrectly Configured Access Control Security Levels.… Mitigation only Fix from $1,6002025-12-09 HIGH 8.8 CVE-2022-47425 Missing Authorization vulnerability in Repute Infosystems ARMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… Armember 3.4.11+ Fix from $1,9502025-12-09 MEDIUM 5.3 CVE-2025-67583 Missing Authorization vulnerability in Foysal Imran IDonate idonate allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… Idonate 2.1.16+ Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-67584 Missing Authorization vulnerability in rtCamp GoDAM godam allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects … Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-67577 Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Sec… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-67578 Missing Authorization vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Exploiting Incorrectly Configured Access Control Security … Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-67579 Missing Authorization vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Exploiting Incorrectly Configured Access Control Securi… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-67580 Missing Authorization vulnerability in Constant Contact Constant Contact + WooCommerce constant-contact-woocommerce allows Exploiting Incorrectly Con… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-67581 Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Contr… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-67582 Missing Authorization vulnerability in wbcomdesigns Wbcom Designs lock-my-bp allows Exploiting Incorrectly Configured Access Control Security Levels.… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-67571 Missing Authorization vulnerability in WPFunnels WPFunnels wpfunnels allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-67572 Missing Authorization vulnerability in PenciDesign PenNews pennews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… Mitigation only Fix from $1,6002025-12-09