Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.1 CVE-2025-65021 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists i… Rallly 4.5.4+ Fix from $2,3002025-11-19 MEDIUM 6.5 CVE-2025-12174 The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a… Mitigation only Fix from $1,6002025-11-19 HIGH 7.5 CVE-2025-12955 The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39.… Mitigation only Fix from $1,9502025-11-18 MEDIUM 5.3 CVE-2025-12391 The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hand… Mitigation only Fix from $1,6002025-11-18 MEDIUM 5.3 CVE-2025-12392 The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… Mitigation only Fix from $1,6002025-11-18 MEDIUM 5.4 CVE-2025-11734 The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to unauthorized post modificati… Mitigation only Fix from $1,6002025-11-18 MEDIUM 6.5 CVE-2025-12937 The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ac… Mitigation only Fix from $1,6002025-11-18 HIGH 7.2 CVE-2025-11620 The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mrpu_ad… Mitigation only Fix from $1,9502025-11-18 MEDIUM 5.3 CVE-2025-12849 The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugi… Mitigation only Fix from $1,6002025-11-15 MEDIUM 6.5 CVE-2025-13179 A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects so… Wholesale after 2025-10-16 Fix from $1,6002025-11-14 HIGH 8.8 CVE-2025-13177 A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site reque… Saleserp after 2025-10-16 Fix from $1,9502025-11-14 MEDIUM 6.5 CVE-2025-13119 A flaw has been found in Fabian Ros/SourceCodester Simple E-Banking System 1.0. This affects an unknown part. This manipulation causes cross-site req… Simple E Banking System No fix yet Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-64384 Missing Authorization vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-64277 Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… Mitigation only Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-64369 Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Se… Mitigation only Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-64370 Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec… Mitigation only Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-64276 Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This… Mitigation only Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-64259 Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security L… Mitigation only Fix from $1,6002025-11-13 MEDIUM 5.4 CVE-2025-64261 Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Exploiting Incorrectly Configured … Mitigation only Fix from $1,6002025-11-13 MEDIUM 5.4 CVE-2025-64263 Missing Authorization vulnerability in PluginEver WP Content Pilot wp-content-pilot allows Exploiting Incorrectly Configured Access Control Security … Mitigation only Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-12891 The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results'… Mitigation only Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-12892 The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_o… Mitigation only Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-12979 The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' acti… Mitigation only Fix from $1,6002025-11-13 HIGH 7.3 CVE-2025-13063 A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. Th… Mitigation only Fix from $1,9502025-11-12 MEDIUM 5.3 CVE-2025-64407 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,6002025-11-12 MEDIUM 6.5 CVE-2025-64402 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,6002025-11-12 HIGH 8.1 CVE-2025-64403 Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in… Openoffice 4.1.16+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-64404 Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft… Openoffice 4.1.16+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-64405 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-64401 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,9502025-11-12