Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-6720 The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in… Mitigation only Fix from $1,6002025-07-19 MEDIUM 5.3 CVE-2025-6721 The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mrkv_vchasno_kasa_wc_do_m… Mitigation only Fix from $1,6002025-07-19 HIGH 8.8 CVE-2025-49747 Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. Azure Machine Learning Mitigation only Fix from $1,9502025-07-18 MEDIUM 6.5 CVE-2025-7772 The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up t… Mitigation only Fix from $1,6002025-07-18 HIGH 8.8 CVE-2025-6718 The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX action in all versions up to… Mitigation only Fix from $1,9502025-07-18 MEDIUM 5.3 CVE-2025-5811 The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the … Mitigation only Fix from $1,6002025-07-18 HIGH 8.8 CVE-2025-6813 The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() functio… Mitigation only Fix from $1,9502025-07-18 MEDIUM 5.3 CVE-2025-3871 Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoA… Mitigation only Fix from $1,6002025-07-16 HIGH 7.5 CVE-2025-52803 Missing Authorization vulnerability in uxper Sala allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sala: from n/a … Mitigation only Fix from $1,9502025-07-16 HIGH 7.5 CVE-2025-52804 Missing Authorization vulnerability in uxper Nuss nuss allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Nuss: from … Mitigation only Fix from $1,9502025-07-16 MEDIUM 6.5 CVE-2025-49884 Missing Authorization vulnerability in alexvtn Internal Linking of Related Contents internal-linking-of-related-contents allows Exploiting Incorrectl… Mitigation only Fix from $1,6002025-07-16 HIGH 7.1 CVE-2025-49888 Missing Authorization vulnerability in pimwick PW WooCommerce On Sale! pw-woocommerce-on-sale allows Exploiting Incorrectly Configured Access Control… Mitigation only Fix from $1,9502025-07-16 MEDIUM 6.5 CVE-2025-50028 Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifications allows Exploiting Incorrectly Configured Acce… Mitigation only Fix from $1,6002025-07-16 MEDIUM 6.5 CVE-2025-48339 Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrectly Configured Access Control … Mitigation only Fix from $1,6002025-07-16 MEDIUM 6.5 CVE-2025-49319 Missing Authorization vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Exploiting Incorrectly Configured Access C… Mitigation only Fix from $1,6002025-07-16 MEDIUM 6.5 CVE-2025-30959 Missing Authorization vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocommerce allows Exploiting Incorre… Mitigation only Fix from $1,6002025-07-16 HIGH 8.6 CVE-2025-28965 Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Accessing Functionality Not Properly Constrained by ACLs.… Mitigation only Fix from $1,9502025-07-16 HIGH 7.5 CVE-2025-29000 Missing Authorization vulnerability in August Infotech Multi-language Responsive Contact Form responsive-contact-form allows Accessing Functionality … Mitigation only Fix from $1,9502025-07-16 MEDIUM 5.4 CVE-2025-54037 Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Acces… Mitigation only Fix from $1,6002025-07-16 MEDIUM 5.3 CVE-2025-53986 Missing Authorization vulnerability in themeisle Hestia hestia allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hes… Mitigation only Fix from $1,6002025-07-16 MEDIUM 5.3 CVE-2025-48166 Missing Authorization vulnerability in sminozzi Stop and Block bots plugin Anti bots antibots allows Accessing Functionality Not Properly Constrained… Mitigation only Fix from $1,6002025-07-16 MEDIUM 5.4 CVE-2025-48167 Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Exploiting Incorrectly Configured Access Control Security Le… Mitigation only Fix from $1,6002025-07-16 MEDIUM 5.3 CVE-2025-48155 Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection allows Accessing Functionality N… Mitigation only Fix from $1,6002025-07-16 HIGH 8.8 CVE-2025-6993 The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX… Ultimate Wp Mail 1.3.7+ Fix from $1,9502025-07-16 HIGH 8.1 CVE-2025-6043 The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Deletion due to a missing… Mitigation only Fix from $1,9502025-07-16 MEDIUM 6.5 CVE-2025-49829 Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authentica… Conjur 1.22.1 / 13.5.1+ Fix from $1,6002025-07-15 HIGH 7.6 CVE-2025-53959 In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible Youtrack 2024.3.85077 / 2025.1.86199+ Fix from $1,9502025-07-15 CRITICAL 9.8 CVE-2025-5394EPSS 49% The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability c… Mitigation only Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-53825 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokplo… Dokploy 0.24.3+ Fix from $2,3002025-07-14 MEDIUM 6.5 CVE-2025-53640 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to… Indico 3.3.7+ Fix from $1,6002025-07-14