Total
6931 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-58601 | 2025-09-04 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in RadiusTheme Classified Listing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Classified Listing: from n/a through 5.0.6.
|
|||||
| CVE-2025-58617 | 2025-09-04 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in FAKTOR VIER F4 Media Taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects F4 Media Taxonomies: from n/a through 1.1.4.
|
|||||
| CVE-2025-8268 | 2025-09-04 | N/A | 6.5 MEDIUM | ||
|
The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delete_files functions in all versions up to, and including, 2.9.5. This makes it possible for unauthenticated attackers to list and delete files uploaded by other users.
|
|||||
| CVE-2025-58622 | 2025-09-04 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in yydevelopment Mobile Contact Line allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mobile Contact Line: from n/a through 2.4.0.
|
|||||
| CVE-2025-58635 | 2025-09-04 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in PalsCode Support Genix allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Support Genix: from n/a through 1.4.23.
|
|||||
| CVE-2025-58594 | 2025-09-04 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in themefusecom Brizy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Brizy: from n/a through 2.7.12.
|
|||||
| CVE-2025-58599 | 2025-09-04 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Delivery Date for WooCommerce: from n/a through 4.1.0.
|
|||||
| CVE-2025-58606 | 2025-09-04 | N/A | 5.0 MEDIUM | ||
|
Missing Authorization vulnerability in CozyThemes SaasLauncher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SaasLauncher: from n/a through 1.3.0.
|
|||||
| CVE-2025-58639 | 2025-09-04 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in Ali Khallad Contact Form By Mega Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Contact Form By Mega Forms: from n/a through 1.6.1.
|
|||||
| CVE-2025-58603 | 2025-09-04 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Surfer Surfer allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Surfer: from n/a through 1.6.4.574.
|
|||||
| CVE-2025-58613 | 2025-09-04 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Barn2 Plugins Posts Table with Search & Sort allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Posts Table with Search & Sort: from n/a through 1.4.10.
|
|||||
| CVE-2025-58616 | 2025-09-04 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Frisbii Frisbii Pay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Frisbii Pay: from n/a through 1.8.2.1.
|
|||||
| CVE-2024-38353 | 1 Hackmd | 1 Codimd | 2025-09-04 | N/A | 5.3 MEDIUM |
|
CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability allowing an unauthenticated attacker to gain unauthorised access to image data uploaded to CodiMD. CodiMD does not require valid authentication to access uploaded images or to upload new image data. An attacker who can determine an uploaded image's URL can gain unauthorised access to uploaded image data. Due to the insecure random filename generatio ...
Show More |
|||||
| CVE-2024-45168 | 1 Uci | 1 Idol2 | 2025-09-03 | N/A | 9.1 CRITICAL |
|
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. Thus, communication endpoints are not verifiable.
|
|||||
| CVE-2022-20358 | 1 Google | 1 Android | 2025-09-03 | N/A | 3.3 LOW |
|
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-203229608
|
|||||
| CVE-2025-46554 | 1 Xwiki | 1 Xwiki | 2025-09-03 | N/A | 5.3 MEDIUM |
|
XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.7.0, anyone can access the metadata of any attachment in the wiki using the wiki attachment REST endpoint. There is no filtering for the results depending on current user rights, meaning an unauthenticated user could exploit this even in a private wiki. This issue has been patched in versions 14.10.22, 15.10. ...
Show More |
|||||
| CVE-2025-46557 | 1 Xwiki | 1 Xwiki | 2025-09-03 | N/A | 9.8 CRITICAL |
|
XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, a user who can access pages located in the XWiki space (by default, anyone) can access the page XWiki.Authentication.Administration and (unless an authenticator is set in xwiki.cfg) switch to another installed authenticator. Note that, by default, there is only one authenticator available (Standard XWiki Authenticator). So, if n ...
Show More |
|||||
| CVE-2025-46811 | 2025-09-03 | N/A | 9.8 CRITICAL | ||
|
A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.27-150600.3.33.1; Image SLES15-SP4-Manager-Server-4-3-BYOS: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2: ...
Show More |
|||||
| CVE-2025-8739 | 1 Zhenfeng13 | 1 My-blog | 2025-09-02 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /admin/tags/save. The manipulation of the argument tagName leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2025-8796 | 1 Litmuschaos | 1 Litmus | 2025-09-02 | 5.5 MEDIUM | 5.4 MEDIUM |
|
A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file /auth/delete_project/ of the component Delete Request Handler. The manipulation of the argument projectID leads to missing authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-8814 | 1 Pybbs Project | 1 Pybbs | 2025-09-02 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function setCookie of the file src/main/java/co/yiiu/pybbs/util/CookieUtil.java. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 8aa2bb1aef3346e49aec6358edf5e47ce905ae7b. It is recommended to apply a patch to fix this issue.
|
|||||
| CVE-2025-31691 | 1 Oauth2 Server Project | 1 Oauth2 Server | 2025-09-02 | N/A | 9.8 CRITICAL |
|
Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.
|
|||||
| CVE-2024-13303 | 1 Download All Files Project | 1 Download All Files | 2025-09-02 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.0.2.
|
|||||
| CVE-2025-0086 | 1 Google | 1 Android | 2025-09-02 | N/A | 6.2 MEDIUM |
|
In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
|
|||||
| CVE-2025-2246 | 1 Gitlab | 1 Gitlab | 2025-09-02 | N/A | 5.8 MEDIUM |
|
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.
|
|||||
| CVE-2024-32589 | 2025-09-02 | N/A | 7.1 HIGH | ||
|
Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.
|
|||||
| CVE-2024-32832 | 2025-09-02 | N/A | 9.8 CRITICAL | ||
|
Missing Authorization vulnerability in Hamid Alinia Login with phone number.This issue affects Login with phone number: from n/a through 1.6.93.
|
|||||
| CVE-2025-54714 | 2025-08-29 | N/A | 7.1 HIGH | ||
|
Missing Authorization vulnerability in Dylan James Zephyr Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zephyr Project Manager: from n/a through 3.3.201.
|
|||||
| CVE-2025-53337 | 2025-08-29 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in Ashan Perera LifePress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LifePress: from n/a through 2.1.3.
|
|||||
| CVE-2025-54710 | 2025-08-29 | N/A | 7.1 HIGH | ||
|
Missing Authorization vulnerability in bPlugins Tiktok Feed allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Tiktok Feed: from n/a through 1.0.21.
|
|||||
| CVE-2025-54733 | 2025-08-29 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Miles All Bootstrap Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects All Bootstrap Blocks: from n/a through 1.3.28.
|
|||||
| CVE-2025-54734 | 2025-08-29 | N/A | 5.8 MEDIUM | ||
|
Missing Authorization vulnerability in bPlugins B Slider allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B Slider: from n/a through 1.1.30.
|
|||||
| CVE-2025-53230 | 2025-08-29 | N/A | 7.6 HIGH | ||
|
Missing Authorization vulnerability in honzat Page Manager for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Page Manager for Elementor: from n/a through 2.0.5.
|
|||||
| CVE-2025-49402 | 2025-08-29 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in favethemes Houzez CRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Houzez CRM: from n/a through 1.4.7.
|
|||||
| CVE-2025-7956 | 2025-08-29 | N/A | 5.3 MEDIUM | ||
|
The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in its AJAX search handler in all versions up to, and including, 4.13.1. This makes it possible for unauthenticated attackers to issue repeated AJAX requests to leak the content of any protected post in rolling 100‑character windows.
|
|||||
| CVE-2025-58198 | 2025-08-29 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Xpro Xpro Theme Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Xpro Theme Builder: from n/a through 1.2.9.
|
|||||
| CVE-2025-58201 | 2025-08-29 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in AfterShip & Automizely AfterShip Tracking allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AfterShip Tracking: from n/a through 1.17.17.
|
|||||
| CVE-2025-48350 | 2025-08-29 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Neuralabz LTD AutoWP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AutoWP: from n/a through 2.2.2.
|
|||||
| CVE-2025-0951 | 2025-08-29 | N/A | 4.3 MEDIUM | ||
|
Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate all of a site's plugins. While we escalated this to Envato after not being able to establish contact, it appears the developer added a nonce check, however that is not sufficient protection as the n ...
Show More |
|||||
| CVE-2025-58193 | 2025-08-29 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Uncanny Automator: from n/a through 6.7.0.1.
|
|||||