Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.4 CVE-2025-8423 The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtswpt_remove_pl… Mitigation only Fix from $1,6002025-09-11 HIGH 8.8 CVE-2025-8425 The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing ca… Mitigation only Fix from $1,9502025-09-11 MEDIUM 5.3 CVE-2025-8492 The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification … Mitigation only Fix from $1,6002025-09-11 MEDIUM 5.8 CVE-2025-36756 A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known. Mitigation only Fix from $1,6002025-09-10 HIGH 7.7 CVE-2025-10040 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability… Mitigation only Fix from $1,9502025-09-10 HIGH 7.8 CVE-2025-49459 Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authenticated user to conduct an escal… Mitigation only Fix from $1,9502025-09-09 HIGH 7.5 CVE-2025-58753 Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option… Copyparty 1.19.8+ Fix from $1,9502025-09-09 MEDIUM 5.3 CVE-2025-58980 Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Accessing Functionality Not Prop… Mitigation only Fix from $1,6002025-09-09 MEDIUM 5.4 CVE-2025-58981 Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly… No fix yet Fix from $1,6002025-09-09 MEDIUM 5.3 CVE-2025-58978 Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Incorrectly Configured Access Con… Mitigation only Fix from $1,6002025-09-09 MEDIUM 5.3 CVE-2025-58979 Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… Mitigation only Fix from $1,6002025-09-09 MEDIUM 5.3 CVE-2025-53348 Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… Mitigation only Fix from $1,6002025-09-09 MEDIUM 5.3 CVE-2025-49860 Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.… No fix yet Fix from $1,6002025-09-09 MEDIUM 5.4 CVE-2025-53291 Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a through <= 2.1.5. Mitigation only Fix from $1,6002025-09-09 MEDIUM 5.3 CVE-2025-53340 Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awes… Mitigation only Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-39541 Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affects WP Simple Booking Calenda… Mitigation only Fix from $1,6002025-09-09 MEDIUM 5.4 CVE-2025-32688 Missing Authorization vulnerability in Nebojsa Target Video Easy Publish brid-video-easy-publish.This issue affects Target Video Easy Publish: from n… Mitigation only Fix from $1,6002025-09-09 HIGH 7.6 CVE-2025-55148 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723… Connect Secure 22.7 / 22.8+ Fix from $1,9502025-09-09 MEDIUM 5.4 CVE-2025-8712 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-72… Neurons For Secure Access 22.7 / 22.8+ Fix from $1,6002025-09-09 HIGH 8.8 CVE-2025-55142 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723… Connect Secure 22.7 / 22.8+ Fix from $1,9502025-09-09 MEDIUM 5.4 CVE-2025-55144 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723… Connect Secure 22.7 / 22.8+ Fix from $1,6002025-09-09 HIGH 8.9 CVE-2025-55145 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723… Neurons For Secure Access 22.7 / 22.8+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-55141 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723… Connect Secure 22.7 / 22.8+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-59017 Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13… TYPO3 9.5.55 / 10.4.54+ Fix from $1,9502025-09-09 MEDIUM 5.4 CVE-2025-9542 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unautho… Mitigation only Fix from $1,6002025-09-09 MEDIUM 5.4 CVE-2025-42915 Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functio… Mitigation only Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-42917 SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation o… Mitigation only Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-42912 SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of priv… Mitigation only Fix from $1,6002025-09-09 HIGH 7.2 CVE-2025-57817 Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver … Fides 2.69.1+ Fix from $1,9502025-09-08 HIGH 8.4 CVE-2024-36326 Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a standby state, potentially r… Mitigation only Fix from $1,9502025-09-06