Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2025-58334 In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves Ide Services 2025.4.2.2164 / 2025.5.0.1086+ Fix from $1,9502025-08-28 MEDIUM 5.8 CVE-2025-54734 Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue … Mitigation only Fix from $1,6002025-08-28 MEDIUM 6.5 CVE-2025-54733 Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting Incorrectly Configured Access… Mitigation only Fix from $1,6002025-08-28 HIGH 7.1 CVE-2025-54714 Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Cont… Mitigation only Fix from $1,9502025-08-28 HIGH 7.1 CVE-2025-54710 Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality Not Properly Constrained by ACLs.This issue … Mitigation only Fix from $1,9502025-08-28 MEDIUM 5.4 CVE-2025-53337 Missing Authorization vulnerability in Ashan Perera LifePress lifepress allows Exploiting Incorrectly Configured Access Control Security Levels.This … No fix yet Fix from $1,6002025-08-28 HIGH 7.6 CVE-2025-53230 Missing Authorization vulnerability in honzat Page Manager for Elementor page-manager-for-elementor allows Exploiting Incorrectly Configured Access C… Mitigation only Fix from $1,9502025-08-28 MEDIUM 5.3 CVE-2025-48327 Missing Authorization vulnerability in inkthemes WP Mailgun SMTP wp-mailgun-smtp allows Accessing Functionality Not Properly Constrained by ACLs.This… Mitigation only Fix from $1,6002025-08-28 MEDIUM 5.3 CVE-2025-7956 The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in its AJAX search handler in all … Mitigation only Fix from $1,6002025-08-28 MEDIUM 5.3 CVE-2025-2246 An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed… GitLab 18.1.5 / 18.2.5+ Fix from $1,6002025-08-27 MEDIUM 6.5 CVE-2025-58198 Missing Authorization vulnerability in Xpro Xpro Theme Builder xpro-theme-builder allows Exploiting Incorrectly Configured Access Control Security Le… Mitigation only Fix from $1,6002025-08-27 MEDIUM 5.3 CVE-2025-58201 Missing Authorization vulnerability in AfterShip & Automizely AfterShip Tracking aftership-woocommerce-tracking allows Accessing Functionality Not Pr… Mitigation only Fix from $1,6002025-08-27 MEDIUM 5.4 CVE-2025-58192 Missing Authorization vulnerability in Xylus Themes WP Bulk Delete wp-bulk-delete allows Exploiting Incorrectly Configured Access Control Security Le… Wp Bulk Delete 1.3.7+ Fix from $1,6002025-08-27 MEDIUM 6.2 CVE-2025-0086 In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to loca… Android Mitigation only Fix from $1,6002025-08-26 MEDIUM 6.5 CVE-2025-48108 Missing Authorization vulnerability in Mojoomla School Management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue … Mitigation only Fix from $1,6002025-08-26 MEDIUM 5.3 CVE-2025-7821 The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pluswc_logo_favicon_log… Mitigation only Fix from $1,6002025-08-23 HIGH 8.1 CVE-2025-55741 UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the… Unopim 0.3.1+ Fix from $1,9502025-08-22 MEDIUM 5.3 CVE-2025-57896 Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.T… Mitigation only Fix from $1,6002025-08-22 CRITICAL 9.8 CVE-2025-52352 Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign… Mitigation only Fix from $2,3002025-08-21 MEDIUM 6.5 CVE-2025-54040 Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Incorrectly Configured Access Con… Mitigation only Fix from $1,6002025-08-20 MEDIUM 6.5 CVE-2025-54025 Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Exploiting Incorrectly Configured Access Co… Mitigation only Fix from $1,6002025-08-20 HIGH 8.5 CVE-2025-49406 Missing Authorization vulnerability in favethemes Houzez allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Houzez: … Mitigation only Fix from $1,9502025-08-20 MEDIUM 6.5 CVE-2025-55734 flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but no… Flaskblog after 2.8.0 Fix from $1,6002025-08-19 HIGH 8.5 CVE-2025-4046 A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization Mitigation only Fix from $1,9502025-08-19 MEDIUM 5.3 CVE-2025-7499 The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers… Mitigation only Fix from $1,6002025-08-16 CRITICAL 9.8 CVE-2025-8898 The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up t… Mitigation only Fix from $2,3002025-08-16 HIGH 7.5 CVE-2025-7664 The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the check_activate_permission() permission… Mitigation only Fix from $1,9502025-08-16 HIGH 7.6 CVE-2025-8361 Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: from 0.0.0 before 2.18.0. Config Pages 2.18.0+ Fix from $1,9502025-08-15 MEDIUM 5.3 CVE-2025-49432 Missing Authorization vulnerability in FWDesign Ultimate Video Player fwduvp allows Exploiting Incorrectly Configured Access Control Security Levels.… Mitigation only Fix from $1,6002025-08-15 HIGH 8.1 CVE-2025-8342 The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty v… Mitigation only Fix from $1,9502025-08-15