Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified CRITICAL 9.3
CVE-2024-8074

Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by …

Mitigation only
Fix from $2,300 2024-11-12
Unclassified MEDIUM 6.5
CVE-2024-42372

Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted glo…

Mitigation only
Fix from $1,600 2024-11-12
Unclassified CRITICAL 9.8
CVE-2024-10589

The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation d…

Mitigation only
Fix from $2,300 2024-11-09
Unclassified HIGH 8.8
CVE-2024-10673

The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_inst…

Mitigation only
Fix from $1,950 2024-11-09
Unclassified HIGH 8.8
CVE-2024-10674

The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_ma…

Mitigation only
Fix from $1,950 2024-11-09
Ce21 Suite HIGH 7.5
CVE-2024-10294

The CE21 Suite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ce21_single_sign_on_…

Fix: after 2.2.0
Fix from $1,950 2024-11-09
Unclassified CRITICAL 9.8
CVE-2024-10586

The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and m…

Mitigation only
Fix from $2,300 2024-11-09
Unclassified CRITICAL 9.8
CVE-2024-48073

sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is responsible for updating the …

Mitigation only
Fix from $2,300 2024-11-08
Enterprise Server MEDIUM 6.5
CVE-2024-10824

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret …

Fix: 3.13.2+
Fix from $1,600 2024-11-07
Moodle HIGH 7.5
CVE-2024-43431

A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Eleforms MEDIUM 5.3
CVE-2024-6626

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a miss…

Fix: after 2.9.9.9
Fix from $1,600 2024-11-06
Video Gallery For Woocommerce MEDIUM 5.3
CVE-2024-10535

The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the re…

Fix: 1.32+
Fix from $1,600 2024-11-06
Harmonyos MEDIUM 5.5
CVE-2024-51516

Permission control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to function abnormall…

No fix yet
Fix from $1,600 2024-11-05
Image Optimizer HIGH 8.8
CVE-2024-48044

Missing Authorization vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Exploiting Incorrectly Configured Acce…

Fix: 5.6.4+
Fix from $1,950 2024-11-01
Happy Addons For Elementor HIGH 8.8
CVE-2024-48045

Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access…

Fix: 3.12.4+
Fix from $1,950 2024-11-01
Popup Maker CRITICAL 9.8
CVE-2024-47358

Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n/a through <= 1.19.2.

Fix: 1.20.0+
Fix from $2,300 2024-11-01
Elementor Addon Elements HIGH 8.8
CVE-2024-47361

Missing Authorization vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This issue affects Elementor Addon …

Fix: 1.13.7+
Fix from $1,950 2024-11-01
Strong Testimonials HIGH 8.8
CVE-2024-47362

Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3…

Fix: 3.1.17+
Fix from $1,950 2024-11-01
Cubewp HIGH 8.8
CVE-2024-48039

Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Exploiting Incorrectly Configured Access Control Security Levels.…

Fix: 1.1.16+
Fix from $1,950 2024-11-01
Sunshine Photo Cart HIGH 8.8
CVE-2024-47314

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Cont…

Fix: 3.2.9+
Fix from $1,950 2024-11-01
Ads HIGH 8.8
CVE-2024-47317

Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded.This issue affects Ads by WPQuads: from n/a through <= 2.…

Fix: 2.0.85+
Fix from $1,950 2024-11-01
Pwa For Wp \& Amp HIGH 8.8
CVE-2024-47318

Missing Authorization vulnerability in Magazine3 PWA for WP & AMP pwa-for-wp.This issue affects PWA for WP & AMP: from n/a through <= 1.7.72.

Fix: 1.7.73+
Fix from $1,950 2024-11-01
Wp Datepicker CRITICAL 9.8
CVE-2024-47321

Missing Authorization vulnerability in Fahad Mahmood WP Datepicker wp-datepicker.This issue affects WP Datepicker: from n/a through <= 2.1.1.

Fix: 2.1.2+
Fix from $2,300 2024-11-01
Sunshine Photo Cart CRITICAL 9.8
CVE-2024-44038

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Cont…

Fix: 3.2.10+
Fix from $2,300 2024-11-01
Helloasso HIGH 8.8
CVE-2024-44052

Missing Authorization vulnerability in HelloAsso HelloAsso helloasso.This issue affects HelloAsso: from n/a through <= 1.1.10.

Fix: 1.1.11+
Fix from $1,950 2024-11-01
Fluent Support CRITICAL 9.8
CVE-2024-47302

Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security…

Fix: 1.8.1+
Fix from $2,300 2024-11-01
Templately CRITICAL 9.8
CVE-2024-47308

Missing Authorization vulnerability in WPDeveloper Templately templately.This issue affects Templately: from n/a through <= 3.1.2.

Fix: 3.1.3+
Fix from $2,300 2024-11-01
Wheel Of Life CRITICAL 9.8
CVE-2024-47311

Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Lev…

Fix: 1.1.9+
Fix from $2,300 2024-11-01
Woocommerce Multilingual \& Multicurrency HIGH 8.8
CVE-2024-44006

Missing Authorization vulnerability in Amir Helzer WooCommerce Multilingual & Multicurrency woocommerce-multilingual.This issue affects WooCommerce M…

Fix: 5.3.7+
Fix from $1,950 2024-11-01
Contact Form 7 Campaign Monitor Extension CRITICAL 9.8
CVE-2024-44019

Missing Authorization vulnerability in Renzo Johnson Contact Form 7 Campaign Monitor Extension contact-form-7-campaign-monitor-extension.This issue a…

Fix: after 0.4.67
Fix from $2,300 2024-11-01