Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.5 CVE-2025-41113 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' informatio… Canaldenuncia.app 4.4.8+ Fix from $1,9502025-11-04 HIGH 7.5 CVE-2025-41114 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' informatio… Canaldenuncia.app 4.4.8+ Fix from $1,9502025-11-04 HIGH 7.5 CVE-2025-41111 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' informatio… Canaldenuncia.app 4.4.8+ Fix from $1,9502025-11-04 HIGH 7.5 CVE-2025-41112 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' informatio… Canaldenuncia.app 4.4.8+ Fix from $1,9502025-11-04 MEDIUM 5.3 CVE-2025-12350 The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admi… Mitigation only Fix from $1,6002025-11-04 CRITICAL 9.8 CVE-2025-12158 The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabilit… Mitigation only Fix from $2,3002025-11-04 MEDIUM 5.3 CVE-2025-12157 The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_aja… Mitigation only Fix from $1,6002025-11-04 HIGH 7.5 CVE-2025-11890 The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 1.0… Mitigation only Fix from $1,9502025-11-04 MEDIUM 6.5 CVE-2025-11758 The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization check in all versions up to, … Mitigation only Fix from $1,6002025-11-04 HIGH 8.8 CVE-2025-10896 Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of File with Dangerous Type via… Mitigation only Fix from $1,9502025-11-04 MEDIUM 6.5 CVE-2025-63293 FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload… Rise Ultimate Project Manager No fix yet Fix from $1,6002025-11-03 MEDIUM 5.3 CVE-2025-64294 Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue … Mitigation only Fix from $1,6002025-11-03 HIGH 8.8 CVE-2025-36367 IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious acto… I Mitigation only Fix from $1,9502025-11-01 CRITICAL 9.8 CVE-2025-11833EPSS 51% The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data … Mitigation only Fix from $2,3002025-11-01 MEDIUM 5.3 CVE-2025-11816 The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modif… Mitigation only Fix from $1,6002025-11-01 HIGH 7.1 CVE-2025-64348 ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifica… Elog after 3.1.5-20251014 Fix from $1,9502025-10-31 HIGH 8.8 CVE-2025-64349 ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset… Elog after 3.1.5-20251014 Fix from $1,9502025-10-31 MEDIUM 5.3 CVE-2025-12041 The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'erifl_file' AJAX act… Mitigation only Fix from $1,6002025-10-31 MEDIUM 5.3 CVE-2025-11191 The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending o… Mitigation only Fix from $1,6002025-10-31 CRITICAL 9.8 CVE-2024-13994 Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configu… Nagios Xi 2024+ Fix from $2,3002025-10-30 HIGH 8.8 CVE-2023-7317 Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could a… Nagios Xi 2024+ Fix from $1,9502025-10-30 MEDIUM 6.5 CVE-2013-10072 Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly rea… Nagios Xi after 2011 Fix from $1,6002025-10-30 HIGH 8.1 CVE-2025-62712 JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4… Jumpserver 3.10.20 / 4.10.11+ Fix from $1,9502025-10-30 MEDIUM 5.3 CVE-2025-11881 The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mya… Mitigation only Fix from $1,6002025-10-30 MEDIUM 5.3 CVE-2025-10008 The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability chec… Mitigation only Fix from $1,6002025-10-30 HIGH 7.5 CVE-2025-9954 Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5. Dam 1.1.5+ Fix from $1,9502025-10-30 MEDIUM 5.4 CVE-2025-64150 A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to connect to an atta… Publish To Bitbucket after 0.4 Fix from $1,6002025-10-29 MEDIUM 5.4 CVE-2025-64132 Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger bui… Mcp Server 0.86.v7d3355e6a_a_18+ Fix from $1,6002025-10-29 MEDIUM 5.4 CVE-2025-64285 Missing Authorization vulnerability in Premmerce Premmerce Wholesale Pricing for WooCommerce premmerce-woocommerce-wholesale-pricing allows Exploitin… Mitigation only Fix from $1,6002025-10-29 MEDIUM 5.3 CVE-2025-64211 Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows Accessing Functionality Not … Mitigation only Fix from $1,6002025-10-29