Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/m…
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. T…
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-own…
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated us…
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that e…
Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode…
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access…
Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without …
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that…
Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported ver…
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affec…
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal wor…