Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Bold Page Builder HIGH 8.8
CVE-2024-50417

Missing Authorization vulnerability in boldthemes Bold Page Builder bold-page-builder allows Exploiting Incorrectly Configured Access Control Securit…

Fix: 5.1.4+
Fix from $1,950 2024-11-19
Unclassified MEDIUM 5.4
CVE-2024-49689

Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light hd-quiz-save-results-light allows Exploiting Incorrectly Configur…

Mitigation only
Fix from $1,600 2024-11-19
Unclassified HIGH 8.8
CVE-2024-11194

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can …

Mitigation only
Fix from $1,950 2024-11-19
Wordpress Gdpr CRITICAL 9.1
CVE-2024-11069

The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'WordPress_GDPR_Data_Dele…

Fix: 2.0.3+
Fix from $2,300 2024-11-19
Unclassified MEDIUM 5.3
CVE-2024-10486

The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to p…

Mitigation only
Fix from $1,600 2024-11-18
Unclassified MEDIUM 6.4
CVE-2024-10390

The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePre…

Mitigation only
Fix from $1,600 2024-11-18
Bitcoin Core MEDIUM 5.3
CVE-2024-52921

In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.

Fix: 25.0+
Fix from $1,600 2024-11-18
Unclassified CRITICAL 10.0
CVE-2024-52416

Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool:…

Mitigation only
Fix from $2,300 2024-11-16
Postx HIGH 8.8
CVE-2024-10728EPSS 36%

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation du…

Fix: 4.1.17+
Fix from $1,950 2024-11-16
Unclassified MEDIUM 5.4
CVE-2024-11085

The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on several AJAX actions i…

Mitigation only
Fix from $1,600 2024-11-16
Unclassified MEDIUM 5.3
CVE-2024-10861

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a…

Mitigation only
Fix from $1,600 2024-11-16
Android HIGH 7.8
CVE-2017-13314

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul…

Patch available
Fix from $1,950 2024-11-15
Unclassified CRITICAL 9.8
CVE-2024-52382

Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue affects Matix Popup Builder: …

Mitigation only
Fix from $2,300 2024-11-14
Unclassified HIGH 7.5
CVE-2024-52383

Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One ai-auto-tool allows Exploit…

Mitigation only
Fix from $1,950 2024-11-14
Harbor MEDIUM 5.4
CVE-2022-31666

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of ot…

Fix: 2.4.3 / 2.5.2+
Fix from $1,600 2024-11-14
Shared Library Version Override HIGH 8.8
CVE-2024-52554

Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not …

Fix: after 17.v786074c9fce7
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43087

In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the access…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43088

In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due …

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43089

In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc…

Patch available
Fix from $1,950 2024-11-13
Android MEDIUM 5.0
CVE-2024-43090

In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure w…

No fix yet
Fix from $1,600 2024-11-13
Android HIGH 7.8
CVE-2024-34719

In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no a…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-40661

In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission chec…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-40671

In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This …

Mitigation only
Fix from $1,950 2024-11-13
Ecostruxure It Gateway CRITICAL 9.8
CVE-2024-10575

CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connec…

Patch available
Fix from $2,300 2024-11-13
User Extra Fields HIGH 8.8
CVE-2024-10800

The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields(…

Fix: 16.7+
Fix from $1,950 2024-11-13
Hash Elements MEDIUM 5.3
CVE-2024-10802

The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_…

Fix: 1.4.8+
Fix from $1,600 2024-11-13
Kognetiks Chatbot MEDIUM 5.3
CVE-2024-10529

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Fix: 2.1.8+
Fix from $1,600 2024-11-13
Hide Links MEDIUM 5.3
CVE-2024-9578

The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filte…

Fix: after 1.4.2
Fix from $1,600 2024-11-13
Unclassified HIGH 8.8
CVE-2024-10629

The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file type validation in the gpxv_f…

Mitigation only
Fix from $1,950 2024-11-13
Styler For Ninja Forms MEDIUM 6.5
CVE-2024-10717

The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a miss…

Fix: after 3.3.4
Fix from $1,600 2024-11-13