Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Js Help Desk CRITICAL 9.1
CVE-2022-46838

Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Co…

Fix: 2.7.2+
Fix from $2,300 2024-12-13
Js Help Desk MEDIUM 5.4
CVE-2022-46840

Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Co…

Fix: 2.7.2+
Fix from $1,600 2024-12-13
Unclassified MEDIUM 5.3
CVE-2022-46846

Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Trending/Popular Post Slider and Widget allows Exploiting Incorrectly Confi…

Mitigation only
Fix from $1,600 2024-12-13
Sunshine Photo Cart MEDIUM 5.4
CVE-2022-45826

Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This i…

Fix: 2.9.14+
Fix from $1,600 2024-12-13
Unclassified MEDIUM 6.5
CVE-2022-45840

Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Mitigation only
Fix from $1,600 2024-12-13
Unclassified MEDIUM 5.4
CVE-2022-45841

Missing Authorization vulnerability in RoboSoft Robo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…

Mitigation only
Fix from $1,600 2024-12-13
Print Invoice \& Delivery Notes For Woocommerce MEDIUM 6.5
CVE-2022-46795

Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access…

Fix: 4.7.3+
Fix from $1,600 2024-12-13
Unclassified MEDIUM 6.5
CVE-2022-46796

Missing Authorization vulnerability in VillaTheme CURCY allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CU…

Mitigation only
Fix from $1,600 2024-12-13
Unclassified MEDIUM 5.3
CVE-2022-44578

Missing Authorization vulnerability in Pierre JEHAN Owl Carousel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

No fix yet
Fix from $1,600 2024-12-13
Formidable Forms CRITICAL 9.8
CVE-2022-45806

Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security…

Fix: 5.5.5+
Fix from $2,300 2024-12-13
Unclassified HIGH 8.1
CVE-2024-10783

The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due …

Mitigation only
Fix from $1,950 2024-12-13
Xwiki HIGH 8.8
CVE-2024-55879

XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arb…

Fix: 15.10.9 / 16.3.0+
Fix from $1,950 2024-12-12
Xwiki MEDIUM 5.4
CVE-2024-55876

XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on …

Fix: 15.10.9 / 16.3.0+
Fix from $1,600 2024-12-12
Unclassified MEDIUM 5.3
CVE-2024-12265

The Web3 Crypto Payments by DePay for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check…

Mitigation only
Fix from $1,600 2024-12-12
Unclassified HIGH 7.5
CVE-2024-12172

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorize…

Mitigation only
Fix from $1,950 2024-12-12
Unclassified HIGH 8.8
CVE-2024-11443

The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capabi…

Mitigation only
Fix from $1,950 2024-12-12
macOS MEDIUM 5.3
CVE-2024-54466

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13…

Fix: 13.7.2 / 14.7.2+
Fix from $1,600 2024-12-12
Unclassified HIGH 7.1
CVE-2024-11840

The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a…

Mitigation only
Fix from $1,950 2024-12-11
Unclassified MEDIUM 5.3
CVE-2024-11401

Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorizatio…

Mitigation only
Fix from $1,600 2024-12-11
Unclassified CRITICAL 9.8
CVE-2024-45493

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is …

Mitigation only
Fix from $2,300 2024-12-10
Wpforms MEDIUM 6.5
CVE-2024-11205

The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' …

Fix: 1.9.2.2+
Fix from $1,600 2024-12-10
Connectport Lts Firmware HIGH 8.8
CVE-2024-50628

An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local area network to achieve unautho…

Fix: 1.4.12+
Fix from $1,950 2024-12-09
Openmanage Server Administrator HIGH 8.8
CVE-2024-45760

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user co…

Fix: 11.1.0.0+
Fix from $1,950 2024-12-09
Unclassified MEDIUM 6.5
CVE-2024-54218

Missing Authorization vulnerability in thehp AIO Contact aio-contact.This issue affects AIO Contact: from n/a through <= 2.8.1.

Mitigation only
Fix from $1,600 2024-12-09
Unclassified MEDIUM 5.3
CVE-2024-52391

Missing Authorization vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.

Mitigation only
Fix from $1,600 2024-12-09
Jobify CRITICAL 9.8
CVE-2024-52480

Missing Authorization vulnerability in Astoundify Jobify jobify.This issue affects Jobify: from n/a through < 4.3.0.

Fix: 4.2.4+
Fix from $2,300 2024-12-09
Profilepress MEDIUM 5.3
CVE-2023-41953

Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1.

Fix: 4.13.2+
Fix from $1,600 2024-12-09
Unclassified MEDIUM 6.5
CVE-2024-54251

Missing Authorization vulnerability in prodigycommerce Prodigy Commerce prodigy-commerce allows Exploiting Incorrectly Configured Access Control Secu…

Mitigation only
Fix from $1,600 2024-12-09
Unclassified MEDIUM 6.3
CVE-2024-54254

Missing Authorization vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter.This issue affects Message Filter for Contact…

Mitigation only
Fix from $1,600 2024-12-09
Tutor Lms Elementor Addons HIGH 8.8
CVE-2024-53816

Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons.This issue affects Tutor LMS Elementor Addons: f…

Fix: 2.1.6+
Fix from $1,950 2024-12-09