Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.5 CVE-2025-13384 The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due… Mitigation only Fix from $1,9502025-11-22 MEDIUM 5.3 CVE-2025-66113 Missing Authorization vulnerability in ThemeAtelier Better Chat Support for Messenger better-chat-support allows Exploiting Incorrectly Configured Ac… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66114 Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variations-shop-category allows Exp… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66107 Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting I… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66109 Missing Authorization vulnerability in Octolize Shipping Plugins Cart Weight for WooCommerce woo-cart-weight allows Exploiting Incorrectly Configured… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66110 Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66099 Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access Control Security Levels.This … Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66082 Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Leve… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66083 Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Leve… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66086 Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Se… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66071 Missing Authorization vulnerability in tychesoftwares Custom Order Numbers for WooCommerce custom-order-numbers-for-woocommerce allows Exploiting Inc… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66072 Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… No fix yet Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66077 Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… No fix yet Fix from $1,6002025-11-21 MEDIUM 6.5 CVE-2025-66079 Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.4 CVE-2025-66063 Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Acce… Mitigation only Fix from $1,6002025-11-21 MEDIUM 6.5 CVE-2025-66065 Missing Authorization vulnerability in Jegstudio Gutenverse gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This i… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-66060 Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured … Seriously Simple Podcasting 3.14.0+ Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-12170 The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wp_ajax_nopriv_checkbox_clean_… Mitigation only Fix from $1,6002025-11-21 HIGH 8.8 CVE-2025-11985 The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capa… Mitigation only Fix from $1,9502025-11-21 MEDIUM 6.5 CVE-2025-10938 The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to mi… Mitigation only Fix from $1,6002025-11-21 MEDIUM 6.4 CVE-2025-11003 The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due t… Mitigation only Fix from $1,6002025-11-21 MEDIUM 6.5 CVE-2025-9825 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have… GitLab 18.2.8 / 18.3.4+ Fix from $1,6002025-11-21 MEDIUM 6.5 CVE-2025-52670 Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accou… Revive Adserver after 6.0.1 Fix from $1,6002025-11-20 MEDIUM 5.4 CVE-2025-62293 SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authentica… Soplanning 1.55.00+ Fix from $1,6002025-11-20 HIGH 8.1 CVE-2025-13468 A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comm… Alumni Management System No fix yet Fix from $1,9502025-11-20 MEDIUM 5.3 CVE-2025-12778 The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missi… Mitigation only Fix from $1,6002025-11-20 MEDIUM 6.5 CVE-2025-65089 XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no v… Pro Macros 1.27.0+ Fix from $1,6002025-11-19 MEDIUM 6.5 CVE-2025-65028 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a… Rallly 4.5.4+ Fix from $1,6002025-11-19 HIGH 8.1 CVE-2025-65029 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a… Rallly 4.5.4+ Fix from $1,9502025-11-19 MEDIUM 6.5 CVE-2025-65020 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability in the p… Rallly 4.5.4+ Fix from $1,6002025-11-19