Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Event Calendar MEDIUM 5.3
CVE-2022-38067

Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.

Fix: after 1.4.6
Fix from $1,600 2022-09-09
Pop Up HIGH 8.8
CVE-2022-38070

Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress.

Fix: after 1.1.5
Fix from $1,950 2022-09-09
Wp Shop CRITICAL 9.1
CVE-2022-36793

Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.

Fix: after 3.9.6
Fix from $2,300 2022-09-09
About Me CRITICAL 9.8
CVE-2022-36387

Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress.

Fix: after 1.0.12
Fix from $2,300 2022-09-06
About Rentals CRITICAL 9.8
CVE-2022-36427

Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at WordPress.

Fix: after 1.5
Fix from $2,300 2022-09-06
Accommodation System CRITICAL 9.8
CVE-2022-37344

Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress.

Fix: after 1.0.1
Fix from $2,300 2022-09-06
Beaver Builder CRITICAL 9.8
CVE-2022-36425

Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress.

Fix: after 2.5.4.3
Fix from $2,300 2022-09-06
Yukassa For Woocommerce MEDIUM 6.5
CVE-2022-34868

Authenticated Arbitrary Settings Update vulnerability in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.

Fix: 2.3.1+
Fix from $1,600 2022-08-23
The Leads Management System\ MEDIUM 5.3
CVE-2022-35242

Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at WordPress.

Fix: after 3.4.1
Fix from $1,600 2022-08-23
Wp Oauth Server CRITICAL 9.8
CVE-2022-34149

Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.

Fix: after 3.0.4
Fix from $2,300 2022-08-22
Affiliate For Woocommerce HIGH 8.8
CVE-2022-25649

Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress.

Fix: 4.8.0+
Fix from $1,950 2022-08-05
Shortcode Addons HIGH 7.2
CVE-2022-33970

Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.

Fix: 3.2.0+
Fix from $1,950 2022-07-27
Responsive Tabs HIGH 7.2
CVE-2022-36375

Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.

Fix: after 3.6.0
Fix from $1,950 2022-07-25
Flipbox HIGH 7.2
CVE-2022-33969

Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress.

Fix: after 2.6.0
Fix from $1,950 2022-07-25
Social Share Buttons HIGH 8.8
CVE-2022-27235

Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.

Fix: 2.2.4+
Fix from $1,950 2022-07-22
Accordions MEDIUM 5.3
CVE-2022-33198

Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.

Fix: 2.0.3+
Fix from $1,600 2022-07-21
Shortcode Addons MEDIUM 5.3
CVE-2022-34487

Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.

Fix: 3.0.3+
Fix from $1,600 2022-07-21
Endpoint Security HIGH 7.8
CVE-2022-23714

A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could all…

Fix: after 8.2.3
Fix from $1,950 2022-07-06
Hadoop HIGH 8.8
CVE-2021-33036

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run ar…

Fix: 2.10.2 / 3.2.3+
Fix from $1,950 2022-06-15
Platinum Mobile MEDIUM 6.5
CVE-2020-36528

A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken acce…

No fix yet
Fix from $1,600 2022-06-07
Countdown Builder CRITICAL 9.8
CVE-2022-29423

Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.

Fix: after 2.3.2
Fix from $2,300 2022-05-06
Playbooks HIGH 8.8
CVE-2022-1548

Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membe…

Fix: after 1.25.0
Fix from $1,950 2022-05-03
Breeze MEDIUM 5.4
CVE-2022-29444

Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subsc…

Fix: 2.0.3+
Fix from $1,600 2022-05-02
Insight Agent HIGH 7.8
CVE-2022-0237

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execu…

Fix: after 3.1.2.38
Fix from $1,950 2022-03-17
Webos HIGH 7.8
CVE-2022-23731

V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.

No fix yet
Fix from $1,950 2022-03-11
Dolphinscheduler HIGH 8.8
CVE-2021-27644

In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data so…

Fix: 1.3.6+
Fix from $1,950 2021-11-01
Ulisting CRITICAL 9.8
CVE-2021-36879

Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user …

Fix: after 2.0.5
Fix from $2,300 2021-09-27
Metamako Operating System HIGH 7.8
CVE-2021-28497

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be a…

Fix: 0.32.0+
Fix from $1,950 2021-09-09
Guix MEDIUM 5.5
CVE-2021-27851

A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-dae…

Fix: 1.2.0+
Fix from $1,600 2021-04-26
Icx35 Hwc A Firmware HIGH 7.5
CVE-2021-22661

Changing the password on the module webpage does not require the user to type in the current password first. Thus, the password could be changed by a…

Fix: after 1.9.62
Fix from $1,950 2021-02-26