Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-49903 Missing Authorization vulnerability in bdthemes ZoloBlocks zoloblocks allows Exploiting Incorrectly Configured Access Control Security Levels.This is… Mitigation only Fix from $1,6002025-10-22 MEDIUM 5.3 CVE-2025-49906 Missing Authorization vulnerability in StellarWP WPComplete wpcomplete allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff… Mitigation only Fix from $1,6002025-10-22 HIGH 8.2 CVE-2025-49910 Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACL… Mitigation only Fix from $1,9502025-10-22 MEDIUM 5.3 CVE-2025-49376 Missing Authorization vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff… Mitigation only Fix from $1,6002025-10-22 MEDIUM 6.3 CVE-2025-49377 Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Access Control Security Levels.T… Mitigation only Fix from $1,6002025-10-22 MEDIUM 6.5 CVE-2025-48096 Missing Authorization vulnerability in FRESHFACE Custom CSS custom-css-editor allows Exploiting Incorrectly Configured Access Control Security Levels… Mitigation only Fix from $1,6002025-10-22 HIGH 7.5 CVE-2025-30944 Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality Not Properly Constrained by A… Mitigation only Fix from $1,9502025-10-22 HIGH 8.1 CVE-2025-61751 Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P… Financial Services Analytical Applications Infrastructure Mitigation only Fix from $1,9502025-10-21 HIGH 8.1 CVE-2025-9133EPSS 5% A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 th… Zld 5.41+ Fix from $1,9502025-10-21 MEDIUM 6.5 CVE-2025-11372 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This … Patch available Fix from $1,6002025-10-18 MEDIUM 5.4 CVE-2025-11378 The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to … Patch available Fix from $1,6002025-10-18 HIGH 8.6 CVE-2025-62642 The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify u… Restaurant Brands International Assistant after 2025-09-06 Fix from $1,9502025-10-17 HIGH 8.1 CVE-2025-58075 Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using th… Mattermost Server 10.5.11 / 10.10.3+ Fix from $1,9502025-10-16 HIGH 8.1 CVE-2025-58073 Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using th… Mattermost Server 10.5.11 / 10.10.3+ Fix from $1,9502025-10-16 MEDIUM 5.4 CVE-2025-41410 Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allo… Mattermost Server 10.5.11 / 10.10.3+ Fix from $1,6002025-10-16 HIGH 8.8 CVE-2025-10706 The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'cwp_addons_update_… Mitigation only Fix from $1,9502025-10-16 MEDIUM 5.3 CVE-2025-10849 The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_plugin_… Mitigation only Fix from $1,6002025-10-16 MEDIUM 5.3 CVE-2025-11692 The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the downl… Mitigation only Fix from $1,6002025-10-15 MEDIUM 5.3 CVE-2025-11701 The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post statu… Mitigation only Fix from $1,6002025-10-15 HIGH 7.2 CVE-2025-10313 The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scripting and Arbitrary Content Repla… Mitigation only Fix from $1,9502025-10-15 MEDIUM 5.3 CVE-2025-10648 The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … Mitigation only Fix from $1,6002025-10-15 HIGH 8.8 CVE-2025-10299 The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability che… Mitigation only Fix from $1,9502025-10-15 MEDIUM 5.3 CVE-2025-10186 The WhyDonate – FREE Donate button – Crowdfunding – Fundraising plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capa… Mitigation only Fix from $1,6002025-10-15 HIGH 7.6 CVE-2025-33182 NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause corruption of the Linux Devi… Mitigation only Fix from $1,9502025-10-14 HIGH 8.8 CVE-2025-8593 The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is … Mitigation only Fix from $1,9502025-10-11 MEDIUM 5.9 CVE-2025-11380 The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data du… Mitigation only Fix from $1,6002025-10-11 MEDIUM 6.5 CVE-2025-9549 Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before … Facets 2.0.10 / 3.0.1+ Fix from $1,6002025-10-10 HIGH 7.5 CVE-2025-11581 A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the compon… Powerjob after 5.1.2 Fix from $1,9502025-10-10 MEDIUM 5.3 CVE-2025-11580 A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing autho… Powerjob after 5.1.2 Fix from $1,6002025-10-10 MEDIUM 6.1 CVE-2025-8887 Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in … Mitigation only Fix from $1,6002025-10-10