Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2025-57955 Missing Authorization vulnerability in Plugin Devs Post Carousel Slider for Elementor post-carousel-slider-for-elementor allows Exploiting Incorrectl… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.3 CVE-2025-57957 Missing Authorization vulnerability in wpcraft WooMS wooms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.4 CVE-2025-57949 Missing Authorization vulnerability in oggix Ongkoskirim.id ongkoskirim-id allows Exploiting Incorrectly Configured Access Control Security Levels.Th… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.3 CVE-2025-57944 Missing Authorization vulnerability in Skimlinks Skimlinks Affiliate Marketing Tool skimlinks allows Accessing Functionality Not Properly Constrained… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.3 CVE-2025-57939 Missing Authorization vulnerability in Blocksera Image Hover Effects – Elementor Addon image-hover-effects-addon-for-elementor allows Exploiting Inco… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.3 CVE-2025-57921 Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Contro… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.3 CVE-2025-57907 Missing Authorization vulnerability in Heureka Group Heureka heureka allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec… Mitigation only Fix from $1,6002025-09-22 MEDIUM 6.5 CVE-2025-57909 Missing Authorization vulnerability in Rouergue Création Editor Custom Color Palette editor-custom-color-palette allows Exploiting Incorrectly Config… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.3 CVE-2025-57899 Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Accessing Functionality Not Properly Constrained by ACLs… Mitigation only Fix from $1,6002025-09-22 MEDIUM 6.5 CVE-2025-59413 CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attac… Cubecart 6.5.11+ Fix from $1,6002025-09-22 HIGH 8.8 CVE-2025-57605 Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges b… Mitigation only Fix from $1,9502025-09-22 MEDIUM 5.3 CVE-2025-10305 The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_passkey() and passkeys_… Mitigation only Fix from $1,6002025-09-20 HIGH 8.1 CVE-2025-7665 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'ha… Mitigation only Fix from $1,9502025-09-19 MEDIUM 5.4 CVE-2025-8487 The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the kubio-image… Mitigation only Fix from $1,6002025-09-19 CRITICAL 9.8 CVE-2025-10690 The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability che… Mitigation only Fix from $2,3002025-09-19 HIGH 8.1 CVE-2025-8565 The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized acces… Mitigation only Fix from $1,9502025-09-18 HIGH 7.5 CVE-2025-59353 Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for … Dragonfly 2.1.0+ Fix from $1,9502025-09-17 HIGH 7.2 CVE-2025-59416 The Scratch Channel is a news website. If the user makes a fork, they can change the admins and make an article. Since the API uses a POST request, i… Mitigation only Fix from $1,9502025-09-17 MEDIUM 5.3 CVE-2025-59474 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users l… Jenkins 2.516.3 / 2.528+ Fix from $1,6002025-09-17 MEDIUM 5.3 CVE-2025-8999 The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_modules' functio… Mitigation only Fix from $1,6002025-09-17 MEDIUM 5.3 CVE-2025-43805 Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 3… Digital Experience Platform 7.4.3.112 / 2023.Q3.5+ Fix from $1,6002025-09-16 HIGH 8.8 CVE-2025-43358 A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS … Ipados 14.8 / 15.7+ Fix from $1,9502025-09-15 HIGH 7.8 CVE-2025-43341 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to gain … macOS 14.8 / 26.0+ Fix from $1,9502025-09-15 HIGH 8.8 CVE-2025-43329 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, watchOS 26. An … Ipados 26.0+ Fix from $1,9502025-09-15 MEDIUM 5.1 CVE-2025-43311 This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may… macOS 14.8 / 15.7+ Fix from $1,6002025-09-15 HIGH 7.8 CVE-2025-43316 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26, visionOS 26. A malicious app may be able to ga… macOS 26.0+ Fix from $1,9502025-09-15 MEDIUM 6.2 CVE-2025-43318 This issue was addressed with additional entitlement checks. This issue is fixed in macOS Tahoe 26. An app with root privileges may be able to access… macOS 26.0+ Fix from $1,6002025-09-15 HIGH 7.8 CVE-2025-43286 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app … macOS 14.8 / 15.7+ Fix from $1,9502025-09-15 MEDIUM 6.5 CVE-2025-9076 Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious o… Mattermost Server 10.10.2+ Fix from $1,6002025-09-15 HIGH 8.8 CVE-2025-9018 The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'tt_update… Mitigation only Fix from $1,9502025-09-11