Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Youtrack MEDIUM 6.5
CVE-2024-54153

In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

Fix: 2024.3.51866+
Fix from $1,600 2024-12-04
Unclassified HIGH 7.5
CVE-2024-10567

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard'…

Mitigation only
Fix from $1,950 2024-12-04
Veeam Backup \& Replication HIGH 8.1
CVE-2024-42453

A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts…

Fix: 12.3.0.310+
Fix from $1,950 2024-12-04
Unclassified HIGH 8.8
CVE-2024-53938

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by defau…

Mitigation only
Fix from $1,950 2024-12-02
Unclassified MEDIUM 6.5
CVE-2024-49581

Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn'…

Mitigation only
Fix from $1,600 2024-12-02
Unclassified MEDIUM 5.3
CVE-2024-53708

Missing Authorization vulnerability in kekotron AI Quiz ai-quiz allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AI…

Mitigation only
Fix from $1,600 2024-12-02
Unclassified HIGH 7.5
CVE-2024-53605

Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers t…

Mitigation only
Fix from $1,950 2024-12-02
Android HIGH 7.8
CVE-2017-13316

In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local es…

Patch available
Fix from $1,950 2024-11-27
Unclassified MEDIUM 5.3
CVE-2024-10580

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing ca…

Mitigation only
Fix from $1,600 2024-11-27
GitLab HIGH 8.8
CVE-2024-8114

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue a…

Fix: 17.4.5 / 17.5.3+
Fix from $1,950 2024-11-26
Anti Spam HIGH 7.5
CVE-2024-10542EPSS 15%

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an auth…

Fix: 6.44+
Fix from $1,950 2024-11-26
Wyse Management Suite MEDIUM 6.5
CVE-2024-49596

Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access c…

Fix: after 4.4
Fix from $1,600 2024-11-26
Autolab MEDIUM 5.3
CVE-2024-53258

Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download a…

Fix: after 3.0.2
Fix from $1,600 2024-11-25
Unclassified HIGH 7.8
CVE-2024-8272

The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-pro…

Mitigation only
Fix from $1,950 2024-11-25
Wordpress Gym Management System HIGH 8.8
CVE-2024-9941

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gm…

Fix: 67.2.0+
Fix from $1,950 2024-11-23
Woo Product Table HIGH 7.5
CVE-2024-10813

The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all …

Fix: 3.5.2+
Fix from $1,950 2024-11-23
Unclassified HIGH 7.6
CVE-2024-0122

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker may cause an unauthorized action. A success…

No fix yet
Fix from $1,950 2024-11-23
Unclassified CRITICAL 9.8
CVE-2024-0138

NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability mig…

Mitigation only
Fix from $2,300 2024-11-23
Sky Addons For Elementor HIGH 8.1
CVE-2024-11104

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for W…

Fix: 2.6.3+
Fix from $1,950 2024-11-22
Sky Addons For Elementor HIGH 8.1
CVE-2024-11601

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery…

Fix: 2.6.2+
Fix from $1,950 2024-11-22
My Contador Lesr MEDIUM 5.3
CVE-2024-11334

The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportar_registros() …

Fix: 2.1+
Fix from $1,600 2024-11-21
Tutor Lms MEDIUM 5.3
CVE-2024-10393

The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing che…

Fix: after 2.7.6
Fix from $1,600 2024-11-21
Android HIGH 7.8
CVE-2018-9477

In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead …

Patch available
Fix from $1,950 2024-11-20
Android HIGH 7.8
CVE-2018-9469

In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead …

Patch available
Fix from $1,950 2024-11-20
Wp Project Manager MEDIUM 5.3
CVE-2024-10520

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' metho…

Fix: 2.6.15+
Fix from $1,600 2024-11-20
Moodle MEDIUM 6.5
CVE-2024-45689

A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they…

Fix: 4.1.13 / 4.2.10+
Fix from $1,600 2024-11-20
Unclassified MEDIUM 5.4
CVE-2024-10665

The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data due to a missing capability ch…

Mitigation only
Fix from $1,600 2024-11-20
Profilegrid HIGH 8.1
CVE-2024-10900

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa…

Fix: 5.9.3.7+
Fix from $1,950 2024-11-20
Unclassified MEDIUM 5.3
CVE-2024-52395

Missing Authorization vulnerability in QuantumCloud Floating Buttons for WooCommerce shop-assistant-for-woocommerce-jarvis allows Exploiting Incorrec…

Mitigation only
Fix from $1,600 2024-11-19
Unclassified MEDIUM 5.4
CVE-2024-51817

Missing Authorization vulnerability in CodeZel Combo WP Rewrite Slugs combo-wp-rewrite-slugs allows Exploiting Incorrectly Configured Access Control …

Mitigation only
Fix from $1,600 2024-11-19