Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2025-8992 A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site… Mblog after 3.5.0 Fix from $1,6002025-08-15 MEDIUM 6.5 CVE-2025-55712 Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Exp… Mitigation only Fix from $1,6002025-08-14 MEDIUM 5.3 CVE-2025-54739 Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Exploiting Incorrectly Configured Access Contro… Mitigation only Fix from $1,6002025-08-14 MEDIUM 5.3 CVE-2025-54730 Missing Authorization vulnerability in PARETO Digital Embedder for Google Reviews embedder-for-google-reviews allows Accessing Functionality Not Prop… Mitigation only Fix from $1,6002025-08-14 MEDIUM 5.4 CVE-2025-54717 Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.… Mitigation only Fix from $1,6002025-08-14 MEDIUM 6.5 CVE-2025-20301 A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to a… Secure Firewall Management Center Mitigation only Fix from $1,6002025-08-14 MEDIUM 5.4 CVE-2025-54695 Missing Authorization vulnerability in DevItems HT Mega ht-mega-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels… Mitigation only Fix from $1,6002025-08-14 HIGH 7.5 CVE-2025-54692 Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Co… Mitigation only Fix from $1,9502025-08-14 HIGH 7.5 CVE-2025-54679 Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free neon-channel-product-customizer-free allows Exploiting Incorrectly… Mitigation only Fix from $1,9502025-08-14 HIGH 7.3 CVE-2025-52801 Missing Authorization vulnerability in VonStroheim TheBooking thebooking allows Accessing Functionality Not Properly Constrained by ACLs.This issue a… Mitigation only Fix from $1,9502025-08-14 HIGH 7.1 CVE-2025-52775 Missing Authorization vulnerability in Ronik@UnlimitedWP Project Cost Calculator project-cost-calculator allows Exploiting Incorrectly Configured Acc… Mitigation only Fix from $1,9502025-08-14 HIGH 7.1 CVE-2025-52785 Missing Authorization vulnerability in softnwords SMM API smm-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue … Mitigation only Fix from $1,9502025-08-14 HIGH 7.3 CVE-2025-52800 Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Accessing Functionality Not Properly Con… Mitigation only Fix from $1,9502025-08-14 MEDIUM 6.5 CVE-2025-52721 Missing Authorization vulnerability in LCweb Global Gallery allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affec… Mitigation only Fix from $1,6002025-08-14 HIGH 7.5 CVE-2025-52731 Missing Authorization vulnerability in themefunction WordPress Event Manager, Event Calendar and Booking Plugin eventin-pro allows Exploiting Incorre… Mitigation only Fix from $1,9502025-08-14 MEDIUM 6.5 CVE-2025-50029 Missing Authorization vulnerability in Ashish AI Tools artificial-intelligence-auto-content-generator allows Exploiting Incorrectly Configured Access… Mitigation only Fix from $1,6002025-08-14 MEDIUM 6.5 CVE-2025-50031 Missing Authorization vulnerability in syedamirhussain91 DB Backup db-backup allows Exploiting Incorrectly Configured Access Control Security Levels.… Mitigation only Fix from $1,6002025-08-14 HIGH 7.5 CVE-2025-31425 Missing Authorization vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Exploiting Incorrectly Configured Access Control Secur… Mitigation only Fix from $1,9502025-08-14 HIGH 7.5 CVE-2025-30639 Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Access Control Security Levels.Th… Mitigation only Fix from $1,9502025-08-14 MEDIUM 6.5 CVE-2025-30993 Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Exploiting Incorrect… Mitigation only Fix from $1,6002025-08-14 MEDIUM 6.5 CVE-2025-28962 Missing Authorization vulnerability in stefanoai Advanced Google Universal Analytics advanced-google-universal-analytics allows Exploiting Incorrectl… Mitigation only Fix from $1,6002025-08-14 CRITICAL 9.8 CVE-2025-8943EPSS 72% The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inh… Flowise 3.0.1+ Fix from $2,3002025-08-14 CRITICAL 9.1 CVE-2025-50171 Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. Windows Server 2022 10.0.20348.3989 / 10.0.25398.1791+ Fix from $2,3002025-08-12 HIGH 8.8 CVE-2025-8310 Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attack… Virtual Application Delivery Controller 22.9+ Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-8418 The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Arbitrary Plugin Installation in all versions up to, and including,… Mitigation only Fix from $1,9502025-08-12 MEDIUM 5.3 CVE-2025-47444 Missing Authorization vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Exploiting Incorrectly Configured Access Control Sec… Mitigation only Fix from $1,6002025-08-12 HIGH 7.5 CVE-2025-6253 The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inclu… Mitigation only Fix from $1,9502025-08-12 CRITICAL 9.8 CVE-2025-8059 The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_re… Mitigation only Fix from $2,3002025-08-12 MEDIUM 5.3 CVE-2025-8285 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscriptio… Confluence 1.5.0+ Fix from $1,6002025-08-11 MEDIUM 5.0 CVE-2025-54458 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscrip… Confluence 1.5.0+ Fix from $1,6002025-08-11