Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.3 CVE-2022-38067 Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress. Event Calendar after 1.4.6 Fix from $1,6002022-09-09 HIGH 8.8 CVE-2022-38070 Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress. Pop Up after 1.1.5 Fix from $1,9502022-09-09 CRITICAL 9.1 CVE-2022-36793 Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress. Wp Shop after 3.9.6 Fix from $2,3002022-09-09 CRITICAL 9.8 CVE-2022-36387 Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress. About Me after 1.0.12 Fix from $2,3002022-09-06 CRITICAL 9.8 CVE-2022-36427 Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at WordPress. About Rentals after 1.5 Fix from $2,3002022-09-06 CRITICAL 9.8 CVE-2022-37344 Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress. Accommodation System after 1.0.1 Fix from $2,3002022-09-06 CRITICAL 9.8 CVE-2022-36425 Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress. Beaver Builder after 2.5.4.3 Fix from $2,3002022-09-06 MEDIUM 6.5 CVE-2022-34868 Authenticated Arbitrary Settings Update vulnerability in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress. Yukassa For Woocommerce 2.3.1+ Fix from $1,6002022-08-23 MEDIUM 5.3 CVE-2022-35242 Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at WordPress. The Leads Management System\ after 3.4.1 Fix from $1,6002022-08-23 CRITICAL 9.8 CVE-2022-34149 Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress. Wp Oauth Server after 3.0.4 Fix from $2,3002022-08-22 HIGH 8.8 CVE-2022-25649 Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress. Affiliate For Woocommerce 4.8.0+ Fix from $1,9502022-08-05 HIGH 7.2 CVE-2022-33970 Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress. Shortcode Addons 3.2.0+ Fix from $1,9502022-07-27 HIGH 7.2 CVE-2022-36375 Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress. Responsive Tabs after 3.6.0 Fix from $1,9502022-07-25 HIGH 7.2 CVE-2022-33969 Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress. Flipbox after 2.6.0 Fix from $1,9502022-07-25 HIGH 8.8 CVE-2022-27235 Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress. Social Share Buttons 2.2.4+ Fix from $1,9502022-07-22 MEDIUM 5.3 CVE-2022-33198 Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress. Accordions 2.0.3+ Fix from $1,6002022-07-21 MEDIUM 5.3 CVE-2022-34487 Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress. Shortcode Addons 3.0.3+ Fix from $1,6002022-07-21 HIGH 7.8 CVE-2022-23714 A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could all… Endpoint Security after 8.2.3 Fix from $1,9502022-07-06 HIGH 8.8 CVE-2021-33036 In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run ar… Hadoop 2.10.2 / 3.2.3+ Fix from $1,9502022-06-15 MEDIUM 6.5 CVE-2020-36528 A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken acce… Platinum Mobile No fix yet Fix from $1,6002022-06-07 CRITICAL 9.8 CVE-2022-29423 Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress. Countdown Builder after 2.3.2 Fix from $2,3002022-05-06 HIGH 8.8 CVE-2022-1548 Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membe… Playbooks after 1.25.0 Fix from $1,9502022-05-03 MEDIUM 5.4 CVE-2022-29444 Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subsc… Breeze 2.0.3+ Fix from $1,6002022-05-02 HIGH 7.8 CVE-2022-0237 Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execu… Insight Agent after 3.1.2.38 Fix from $1,9502022-03-17 HIGH 7.8 CVE-2022-23731 V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models. Webos No fix yet Fix from $1,9502022-03-11 HIGH 8.8 CVE-2021-27644 In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data so… Dolphinscheduler 1.3.6+ Fix from $1,9502021-11-01 CRITICAL 9.8 CVE-2021-36879 Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user … Ulisting after 2.0.5 Fix from $2,3002021-09-27 HIGH 7.8 CVE-2021-28497 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be a… Metamako Operating System 0.32.0+ Fix from $1,9502021-09-09 MEDIUM 5.5 CVE-2021-27851 A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-dae… Guix 1.2.0+ Fix from $1,6002021-04-26 HIGH 7.5 CVE-2021-22661 Changing the password on the module webpage does not require the user to type in the current password first. Thus, the password could be changed by a… Icx35 Hwc A Firmware after 1.9.62 Fix from $1,9502021-02-26