Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.2 CVE-2025-7040 The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization… Mitigation only Fix from $1,9502025-09-06 MEDIUM 6.5 CVE-2025-53571 Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control … Mitigation only Fix from $1,6002025-09-05 MEDIUM 6.5 CVE-2025-54744 Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured A… No fix yet Fix from $1,6002025-09-05 MEDIUM 5.5 CVE-2024-0028 In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permission check. This could lead to l… Android Mitigation only Fix from $1,6002025-09-05 MEDIUM 5.4 CVE-2025-58785 Missing Authorization vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows Exploiting Incorrectly Configured Access … Mitigation only Fix from $1,6002025-09-05 HIGH 7.8 CVE-2025-22414 In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permission check. This could lead to… Android Mitigation only Fix from $1,9502025-09-04 HIGH 7.3 CVE-2025-48547 In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead to local escalation of privil… Android No fix yet Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-48549 In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escal… Android Patch available Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-48524 In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of … Android Mitigation only Fix from $1,6002025-09-04 MEDIUM 5.5 CVE-2025-26445 In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local i… Android Patch available Fix from $1,6002025-09-04 HIGH 7.8 CVE-2025-26450 In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motion events to the default IME d… Android Patch available Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-26440 In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lea… Android Patch available Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-26437 In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permissi… Android Patch available Fix from $1,6002025-09-04 MEDIUM 6.5 CVE-2025-8268 The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delet… Mitigation only Fix from $1,6002025-09-03 MEDIUM 5.4 CVE-2025-58639 Missing Authorization vulnerability in Ali Khallad Contact Form By Mega Forms mega-forms allows Exploiting Incorrectly Configured Access Control Secu… Mitigation only Fix from $1,6002025-09-03 MEDIUM 5.3 CVE-2025-58634 Missing Authorization vulnerability in peachpay PeachPay Payments peachpay-for-woocommerce allows Exploiting Incorrectly Configured Access Control Se… Mitigation only Fix from $1,6002025-09-03 MEDIUM 5.3 CVE-2025-58635 Missing Authorization vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Lev… Mitigation only Fix from $1,6002025-09-03 MEDIUM 6.5 CVE-2025-58616 Missing Authorization vulnerability in Frisbii Frisbii Pay reepay-checkout-gateway allows Exploiting Incorrectly Configured Access Control Security L… No fix yet Fix from $1,6002025-09-03 MEDIUM 5.3 CVE-2025-58613 Missing Authorization vulnerability in Barn2 Plugins Posts Table with Search & Sort posts-data-table allows Exploiting Incorrectly Configured Access … Mitigation only Fix from $1,6002025-09-03 MEDIUM 5.0 CVE-2025-58606 Missing Authorization vulnerability in cozythemes SaasLauncher saaslauncher allows Exploiting Incorrectly Configured Access Control Security Levels.T… Mitigation only Fix from $1,6002025-09-03 MEDIUM 5.3 CVE-2025-58600 Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access… Mitigation only Fix from $1,6002025-09-03 MEDIUM 5.3 CVE-2025-58603 Missing Authorization vulnerability in Surfer Surfer surferseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… No fix yet Fix from $1,6002025-09-03 CRITICAL 9.8 CVE-2025-58210 Missing Authorization vulnerability in ThemeMove Makeaholic makeaholic allows Exploiting Incorrectly Configured Access Control Security Levels.This i… Makeaholic 1.8.7+ Fix from $2,3002025-09-03 HIGH 7.3 CVE-2025-22439 In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission c… Android Mitigation only Fix from $1,9502025-09-02 HIGH 8.8 CVE-2025-6685 ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected i… Eco Dc 1.2.116+ Fix from $1,9502025-09-02 HIGH 8.8 CVE-2025-9747 A vulnerability has been found in Koillection up to 1.6.18. Affected is an unknown function of the file assets/controllers/csrf_protection_controller… Koillection 1.7.0+ Fix from $1,9502025-08-31 CRITICAL 9.8 CVE-2024-32832 Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from … Mitigation only Fix from $2,3002025-08-31 HIGH 7.1 CVE-2024-32589 Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-m… Mitigation only Fix from $1,9502025-08-31 CRITICAL 9.8 CVE-2025-54943 A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized app… Ehrd Ctms 10.11+ Fix from $2,3002025-08-30 CRITICAL 9.1 CVE-2025-43773 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024… Digital Experience Platform 2024.Q1.19 / 2025.Q1.15+ Fix from $2,3002025-08-29