Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.7 CVE-2025-8886 Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect A… Mitigation only Fix from $1,6002025-10-10 HIGH 8.6 CVE-2025-59968 A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read … Space Security Director 24.1+ Fix from $1,9502025-10-09 CRITICAL 9.3 CVE-2025-10352 Vulnerability in the melis-core module of Melis Technology's Melis Platform, which, if exploited, allows an unauthenticated attacker to create an adm… Mitigation only Fix from $2,3002025-10-08 MEDIUM 6.3 CVE-2025-11438 A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component A… Opnform after 1.9.3 Fix from $1,6002025-10-08 HIGH 8.1 CVE-2025-9243 The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capability check on the get_cc_or… Mitigation only Fix from $1,9502025-10-04 MEDIUM 5.3 CVE-2025-11228 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… Givewp 4.10.1+ Fix from $1,6002025-10-04 MEDIUM 5.3 CVE-2025-10212 The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple fu… Mitigation only Fix from $1,6002025-10-03 CRITICAL 9.1 CVE-2020-36852 The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1,… Mitigation only Fix from $2,3002025-10-01 MEDIUM 6.5 CVE-2025-11051 A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code. The manipulation lead… Pet Grooming Management Software No fix yet Fix from $1,6002025-09-27 HIGH 8.8 CVE-2025-11029 A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site … Vvveb after 1.0.7.2 Fix from $1,9502025-09-26 MEDIUM 5.3 CVE-2025-60155 Missing Authorization vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Exploiting Incorrectly Configured Access Control Security … Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.4 CVE-2025-60127 Missing Authorization vulnerability in ArtistScope CopySafe Web Protection wp-copysafe-web allows Exploiting Incorrectly Configured Access Control Se… Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.3 CVE-2025-60129 Missing Authorization vulnerability in Yext Yext yext allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Yext: from n… No fix yet Fix from $1,6002025-09-26 MEDIUM 5.3 CVE-2025-60130 Missing Authorization vulnerability in wedos.com WEDOS Global wgpwpp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec… Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.3 CVE-2025-60120 Missing Authorization vulnerability in WPDirectoryKit WP Directory Kit wpdirectorykit allows Exploiting Incorrectly Configured Access Control Securit… Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.3 CVE-2025-60121 Missing Authorization vulnerability in Ex-Themes WooEvents woo-events allows Exploiting Incorrectly Configured Access Control Security Levels.This is… No fix yet Fix from $1,6002025-09-26 HIGH 8.8 CVE-2025-60116 Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Exploiting Incorrectly C… Grand Conference 2.6.4+ Fix from $1,9502025-09-26 MEDIUM 6.5 CVE-2025-60098 Missing Authorization vulnerability in Jeff Farthing Theme My Login theme-my-login allows Exploiting Incorrectly Configured Access Control Security L… Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.4 CVE-2025-60103 Missing Authorization vulnerability in CridioStudio ListingPro listingpro-plugin allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.4 CVE-2025-60096 Missing Authorization vulnerability in CodexThemes TheGem (Elementor) thegem-elementor allows Exploiting Incorrectly Configured Access Control Securi… Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.4 CVE-2025-60097 Missing Authorization vulnerability in CodexThemes TheGem thegem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a… No fix yet Fix from $1,6002025-09-26 HIGH 7.5 CVE-2025-59011 Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… Mitigation only Fix from $1,9502025-09-26 MEDIUM 6.5 CVE-2025-48326 Missing Authorization vulnerability in Acclectic Media Acclectic Media Organizer acclectic-media-organizer allows Exploiting Incorrectly Configured A… Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.3 CVE-2025-58919 Missing Authorization vulnerability in guihom Wide Banner wide-banner allows Exploiting Incorrectly Configured Access Control Security Levels.This is… Mitigation only Fix from $1,6002025-09-26 HIGH 7.2 CVE-2025-10871 An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintai… GitLab 18.2.7 / 18.3.3+ Fix from $1,9502025-09-26 MEDIUM 5.3 CVE-2025-9984 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the fifu_ap… Mitigation only Fix from $1,6002025-09-26 HIGH 8.6 CVE-2025-20362 KEVEPSS 87% Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Softwar… Adaptive Security Appliance Software 7.0.8.1 / 7.2.10.2+ Fix from $1,9502025-09-25 HIGH 8.8 CVE-2025-40837 Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher p… Indoor Connect 8855 Firmware 2025.q2+ Fix from $1,9502025-09-25 CRITICAL 9.8 CVE-2025-59827 Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any aut… Flagforge Mitigation only Fix from $2,3002025-09-24 CRITICAL 9.8 CVE-2025-59828 Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.0+, Yarn plugins are auto-exe… Claude Code 1.0.39+ Fix from $2,3002025-09-24