Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.4 CVE-2025-48731 Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscripti… Confluence 1.5.0+ Fix from $1,6002025-08-11 HIGH 8.8 CVE-2025-8807 A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tia… Tianti after 2.3 Fix from $1,9502025-08-10 MEDIUM 5.4 CVE-2025-8796 A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file … Litmus after 3.19.0 Fix from $1,6002025-08-10 MEDIUM 5.3 CVE-2025-51308 In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only end… Gatling 1.25.0+ Fix from $1,6002025-08-06 HIGH 7.8 CVE-2025-41698 A low privileged local attacker can interact with the affected service although user-interaction should not be allowed. No fix yet Fix from $1,9502025-08-05 CRITICAL 9.1 CVE-2025-6205 KEVEPSS 71% A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged acces… Delmia Apriso 2025+ Fix from $2,3002025-08-04 HIGH 8.8 CVE-2025-6754 The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect… Mitigation only Fix from $1,9502025-08-02 MEDIUM 5.3 CVE-2025-8152 The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… Mitigation only Fix from $1,6002025-08-02 HIGH 7.3 CVE-2025-8435 A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by this vulnerability is an unknown… Online Movie Streaming No fix yet Fix from $1,9502025-08-01 HIGH 7.3 CVE-2025-8434 A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is an unknown function of the fil… Online Movie Streaming No fix yet Fix from $1,9502025-08-01 MEDIUM 6.5 CVE-2025-53111 GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized acc… Glpi 10.0.19+ Fix from $1,6002025-07-30 CRITICAL 9.8 CVE-2025-46811EPSS 10% A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any … Mitigation only Fix from $2,3002025-07-30 HIGH 8.8 CVE-2025-8322 The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator function… Mitigation only Fix from $1,9502025-07-30 HIGH 8.8 CVE-2025-7689 The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() … Mitigation only Fix from $1,9502025-07-29 MEDIUM 5.3 CVE-2025-4370 The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls funct… Brizy 2.6.21+ Fix from $1,6002025-07-29 HIGH 8.3 CVE-2025-54378 HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 … Haxcms Nodejs 11.0.9 / 11.0.14+ Fix from $1,9502025-07-26 HIGH 7.5 CVE-2023-7306 The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete… Mitigation only Fix from $1,9502025-07-25 HIGH 8.8 CVE-2025-5835 The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis… Droip after 2.2.0 Fix from $1,9502025-07-25 CRITICAL 9.8 CVE-2015-10143 The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability… Platform Theme 1.4.4+ Fix from $2,3002025-07-25 HIGH 8.8 CVE-2025-7695 The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_li… Mitigation only Fix from $1,9502025-07-24 CRITICAL 9.8 CVE-2025-6441 The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable t… Mitigation only Fix from $2,3002025-07-24 CRITICAL 9.8 CVE-2025-6380 The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in v… Mitigation only Fix from $2,3002025-07-24 MEDIUM 5.3 CVE-2025-6215 The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/regist… Mitigation only Fix from $1,6002025-07-23 HIGH 8.8 CVE-2025-6190 The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the rp_user_profile() AJAX h… Mitigation only Fix from $1,9502025-07-23 HIGH 8.8 CVE-2015-10140 The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscribe… Ajax Load More 2.8.1.2+ Fix from $1,9502025-07-22 CRITICAL 9.8 CVE-2025-6187 The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_info REST endpoint in versions 1… Mitigation only Fix from $2,3002025-07-22 HIGH 7.5 CVE-2025-7717 Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: from 0.0.0 before 1.9.0, from … File Download 8.x-1.9+ Fix from $1,9502025-07-21 MEDIUM 6.5 CVE-2025-43720 Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user ro… Headwind Mdm 5.33.1+ Fix from $1,6002025-07-21 MEDIUM 5.5 CVE-2025-43976 The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone ca… 2ndline No fix yet Fix from $1,6002025-07-21 MEDIUM 5.5 CVE-2025-43977 The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without u… Com.skt.prod.dialer Mitigation only Fix from $1,6002025-07-21