Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.8 CVE-2025-13342 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to… Mitigation only Fix from $2,3002025-12-03 MEDIUM 5.4 CVE-2025-12887 The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not p… Mitigation only Fix from $1,6002025-12-03 MEDIUM 5.3 CVE-2025-13472 A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like cre… Mitigation only Fix from $1,6002025-12-03 MEDIUM 5.3 CVE-2025-10304 The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a m… Mitigation only Fix from $1,6002025-12-03 CRITICAL 9.0 CVE-2025-13828 SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settin… Mitigation only Fix from $2,3002025-12-02 MEDIUM 5.3 CVE-2025-41012 Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a use… Gim 2025-04-01+ Fix from $1,6002025-12-02 HIGH 8.1 CVE-2025-13813 A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the componen… Mogublog after 5.2 Fix from $1,9502025-12-01 HIGH 8.8 CVE-2025-13790 A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The… Scada Lts after 2.7.8.1 Fix from $1,9502025-11-30 CRITICAL 9.8 CVE-2025-65112 PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated use… Pubnet 1.1.4+ Fix from $2,3002025-11-29 MEDIUM 5.3 CVE-2025-13381 The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … Mitigation only Fix from $1,6002025-11-27 MEDIUM 5.3 CVE-2025-13441 The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.… Mitigation only Fix from $1,6002025-11-27 MEDIUM 5.3 CVE-2025-12579 The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'logoff' action i… Mitigation only Fix from $1,6002025-11-27 CRITICAL 9.1 CVE-2025-65669 An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authent… Classroomio No fix yet Fix from $2,3002025-11-26 HIGH 7.5 CVE-2025-55471 Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users. Youlai Boot No fix yet Fix from $1,9502025-11-26 HIGH 7.5 CVE-2025-46175 Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserContr… Ruoyi Mitigation only Fix from $1,9502025-11-26 HIGH 7.5 CVE-2025-46174 Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserControll… Ruoyi Mitigation only Fix from $1,9502025-11-26 HIGH 8.6 CVE-2025-12061 The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users… Mitigation only Fix from $1,9502025-11-26 CRITICAL 9.8 CVE-2025-66022 FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension fra… Faction 1.7.1+ Fix from $2,3002025-11-26 MEDIUM 5.3 CVE-2025-13404 The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing authorization validation on the dup… Mitigation only Fix from $1,6002025-11-25 MEDIUM 5.3 CVE-2025-13405 The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing authorization validation on the … Mitigation only Fix from $1,6002025-11-25 MEDIUM 5.3 CVE-2025-13414 The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing capability check on the cdas… Mitigation only Fix from $1,6002025-11-25 MEDIUM 5.3 CVE-2025-13386 The Social Images Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'options_up… Mitigation only Fix from $1,6002025-11-25 MEDIUM 5.3 CVE-2025-12043 The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the … Mitigation only Fix from $1,6002025-11-25 MEDIUM 6.5 CVE-2025-13643 A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. Th… MongoDB 7.0.26 / 8.0.14+ Fix from $1,6002025-11-25 MEDIUM 5.4 CVE-2025-13558 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… Mitigation only Fix from $1,6002025-11-25 HIGH 8.7 CVE-2025-41016 Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm … Mitigation only Fix from $1,9502025-11-24 MEDIUM 6.9 CVE-2025-41017 Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve perspective parameters from secur… Mitigation only Fix from $1,6002025-11-24 MEDIUM 5.3 CVE-2025-13318 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is d… Mitigation only Fix from $1,6002025-11-22 MEDIUM 5.3 CVE-2025-12877 The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a mi… Idonate 2.1.16+ Fix from $1,6002025-11-22 MEDIUM 5.3 CVE-2025-13317 The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is du… Mitigation only Fix from $1,6002025-11-22