Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-12891 The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results'… Mitigation only Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-12892 The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_o… Mitigation only Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-12979 The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' acti… Mitigation only Fix from $1,6002025-11-13 HIGH 7.3 CVE-2025-13063 A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. Th… Mitigation only Fix from $1,9502025-11-12 MEDIUM 5.3 CVE-2025-64407 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,6002025-11-12 MEDIUM 6.5 CVE-2025-64402 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,6002025-11-12 HIGH 8.1 CVE-2025-64403 Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in… Openoffice 4.1.16+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-64404 Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft… Openoffice 4.1.16+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-64405 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-64401 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-12633 The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… Mitigation only Fix from $1,9502025-11-12 HIGH 8.1 CVE-2025-30398 Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. Nuance Powerscribe 360 Mitigation only Fix from $1,9502025-11-11 MEDIUM 5.3 CVE-2025-33185 NVIDIA AIStore contains a vulnerability in AuthN where an unauthenticated user may cause information disclosure.  A successful exploit of this vulner… Mitigation only Fix from $1,6002025-11-11 MEDIUM 5.5 CVE-2025-5317 An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with admini… Endpoint Security 7.20.52.200087+ Fix from $1,6002025-11-11 MEDIUM 5.3 CVE-2025-11996 The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() an… Find Unused Images after 1.0.7 Fix from $1,6002025-11-11 MEDIUM 5.3 CVE-2025-11999 The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultip… Mitigation only Fix from $1,6002025-11-11 MEDIUM 5.3 CVE-2025-11894 The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpo… Mitigation only Fix from $1,6002025-11-11 MEDIUM 5.3 CVE-2025-11988 The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plu… Mitigation only Fix from $1,6002025-11-11 HIGH 7.5 CVE-2025-64684 In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form Youtrack 2025.3.104432+ Fix from $1,9502025-11-10 MEDIUM 6.5 CVE-2025-12924 A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the fi… Forest after 2025-09-07 Fix from $1,6002025-11-10 CRITICAL 9.8 CVE-2025-12925 A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/… Forest after 2025-09-04 Fix from $2,3002025-11-10 MEDIUM 6.5 CVE-2025-7663 The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /… Mitigation only Fix from $1,6002025-11-08 MEDIUM 5.3 CVE-2025-12042 The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in the csv-export.php f… Mitigation only Fix from $1,6002025-11-08 MEDIUM 6.4 CVE-2025-12583 The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_n… Mitigation only Fix from $1,6002025-11-08 MEDIUM 6.5 CVE-2025-4522 The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admi… Idonate 2.1.10+ Fix from $1,6002025-11-07 MEDIUM 5.3 CVE-2025-64323 kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any c… Patch available Fix from $1,6002025-11-07 HIGH 8.1 CVE-2025-5483 The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wizard/inc/wp_user.php file in … Mitigation only Fix from $1,9502025-11-07 MEDIUM 5.3 CVE-2025-64179 lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below, missing authentication in th… Patch available Fix from $1,6002025-11-06 MEDIUM 6.5 CVE-2025-62914 Missing Authorization vulnerability in anibalwainstein Effect Maker effect-maker allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,6002025-11-06 MEDIUM 6.5 CVE-2025-62046 Missing Authorization vulnerability in CodexThemes TheGem Demo Import (for WPBakery) thegem-importer.This issue affects TheGem Demo Import (for WPBak… Mitigation only Fix from $1,6002025-11-06