Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-62151 Missing Authorization vulnerability in Virtuaria Virtuaria PagBank / PagSeguro para Woocommerce virtuaria-pagseguro allows Exploiting Incorrectly Con… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-62152 Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Le… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-62153 Missing Authorization vulnerability in Graham Quick Interest Slider quick-interest-slider allows Exploiting Incorrectly Configured Access Control Sec… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-62085 Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly Configured Access Control Sec… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.4 CVE-2025-62086 Missing Authorization vulnerability in akazanstev Яндекс Доставка (Boxberry) boxberry allows Exploiting Incorrectly Configured Access Control Securit… Mitigation only Fix from $1,6002025-12-09 MEDIUM 6.5 CVE-2025-62090 Missing Authorization vulnerability in Jegstudio Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons gutenverse-news allows Exploit… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-62100 Missing Authorization vulnerability in themerain ThemeRain Core themerain-core allows Exploiting Incorrectly Configured Access Control Security Level… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-49348 Missing Authorization vulnerability in Hype Hype pico allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hype… No fix yet Fix from $1,6002025-12-09 MEDIUM 5.5 CVE-2025-42891 Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and export the contents of database… Mitigation only Fix from $1,6002025-12-09 MEDIUM 5.5 CVE-2025-48608 In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local in… Android Mitigation only Fix from $1,6002025-12-08 HIGH 7.8 CVE-2025-48599 In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permission check. … Android Patch available Fix from $1,9502025-12-08 MEDIUM 5.5 CVE-2025-48600 In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information… Android Mitigation only Fix from $1,6002025-12-08 MEDIUM 5.5 CVE-2025-48604 In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local informatio… Android Patch available Fix from $1,6002025-12-08 MEDIUM 5.5 CVE-2025-48591 In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local informatio… Android Mitigation only Fix from $1,6002025-12-08 HIGH 7.8 CVE-2025-48575 In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass. This could lead to local es… Android Patch available Fix from $1,9502025-12-08 MEDIUM 6.7 CVE-2025-32319 In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. T… Android Patch available Fix from $1,6002025-12-08 MEDIUM 6.5 CVE-2025-14117 A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The … Halo No fix yet Fix from $1,6002025-12-06 MEDIUM 5.3 CVE-2025-13666 The Helloprint plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.2. This is due to the plugin registe… Mitigation only Fix from $1,6002025-12-06 MEDIUM 5.3 CVE-2025-13358 The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing authorization checks in vers… Mitigation only Fix from $1,6002025-12-06 MEDIUM 5.3 CVE-2025-12721 The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_st… Mitigation only Fix from $1,6002025-12-06 HIGH 8.3 CVE-2025-65036 XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Veloc… Pro Macros 1.27.1+ Fix from $1,9502025-12-05 MEDIUM 5.3 CVE-2025-13620 The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. … Mitigation only Fix from $1,6002025-12-05 MEDIUM 5.3 CVE-2025-12876 The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… Mitigation only Fix from $1,6002025-12-05 MEDIUM 5.3 CVE-2025-12355 The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_update_or… Mitigation only Fix from $1,6002025-12-05 MEDIUM 5.3 CVE-2025-12093 The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all… Mitigation only Fix from $1,6002025-12-05 MEDIUM 5.3 CVE-2025-13528 The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_exp… Mitigation only Fix from $1,6002025-12-05 MEDIUM 5.3 CVE-2025-13312 The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_n… Mitigation only Fix from $1,6002025-12-05 CRITICAL 9.8 CVE-2025-13313 The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is … Mitigation only Fix from $2,3002025-12-05 HIGH 7.5 CVE-2025-54159 Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files… Beedrive 1.4.2-13960+ Fix from $1,9502025-12-04 MEDIUM 6.3 CVE-2025-2848 A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical… Mail Server 1.7.6-10676 / 1.7.6-20676+ Fix from $1,6002025-12-04