Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Multi Step Form CRITICAL 9.8
CVE-2024-50428

Missing Authorization vulnerability in mondula2016 Multi Step Form multi-step-form allows Exploiting Incorrectly Configured Access Control Security L…

Fix: 1.7.22+
Fix from $2,300 2024-10-29
Unclassified MEDIUM 5.3
CVE-2024-50454

Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Mitigation only
Fix from $1,600 2024-10-29
Unclassified MEDIUM 5.3
CVE-2024-50421

Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting…

Mitigation only
Fix from $1,600 2024-10-29
Unclassified MEDIUM 5.3
CVE-2024-50422

Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

No fix yet
Fix from $1,600 2024-10-29
Unclassified MEDIUM 5.4
CVE-2024-50423

Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Mitigation only
Fix from $1,600 2024-10-29
Unclassified MEDIUM 6.5
CVE-2024-50424

Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access Control Security Levels.This…

Mitigation only
Fix from $1,600 2024-10-29
Seopress HIGH 8.8
CVE-2024-50455

Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Fix: 8.2+
Fix from $1,950 2024-10-29
Seopress HIGH 8.8
CVE-2024-50456

Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.Th…

Fix: after 8.2
Fix from $1,950 2024-10-29
Aidwp CRITICAL 9.8
CVE-2024-50459

Missing Authorization vulnerability in Hossni Mubarak AidWP wp-stripe-donation allows Exploiting Incorrectly Configured Access Control Security Level…

Fix: 3.2.4+
Fix from $2,300 2024-10-29
Lunary CRITICAL 9.1
CVE-2024-7475

An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization.…

Fix: 1.3.4+
Fix from $2,300 2024-10-29
Unclassified CRITICAL 9.8
CVE-2024-50490

Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects P…

Mitigation only
Fix from $2,300 2024-10-29
Unclassified CRITICAL 9.8
CVE-2024-50475

Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affects Signup Page: from n/a throu…

Mitigation only
Fix from $2,300 2024-10-29
Unclassified CRITICAL 9.8
CVE-2024-50476

Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects…

Mitigation only
Fix from $2,300 2024-10-29
Masteriyo MEDIUM 6.5
CVE-2024-10008

The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification du…

Fix: 1.13.4+
Fix from $1,600 2024-10-29
macOS HIGH 7.5
CVE-2024-44208

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15. An app may be able to bypass certain Privacy pre…

Fix: 15.0+
Fix from $1,950 2024-10-28
macOS HIGH 7.1
CVE-2024-44156

A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Sequoia 15.1, ma…

Fix: 13.7.1 / 14.7.1+
Fix from $1,950 2024-10-28
Unclassified MEDIUM 5.4
CVE-2024-9629

The Contact Form 7 + Telegram plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability ch…

Mitigation only
Fix from $1,600 2024-10-28
Hub MEDIUM 5.4
CVE-2024-50573

In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services

Fix: 2024.3.47707+
Fix from $1,600 2024-10-28
Forminator Forms HIGH 8.8
CVE-2024-10402

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing ca…

Fix: 1.36.0+
Fix from $1,950 2024-10-26
Image Map Pro MEDIUM 5.4
CVE-2024-9584

The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the A…

Fix: after 6.0.20
Fix from $1,600 2024-10-25
Wps Telegram Chat MEDIUM 6.5
CVE-2024-9628

The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on t…

Fix: after 4.5.4
Fix from $1,600 2024-10-25
Wps Telegram Chat MEDIUM 5.3
CVE-2024-9630

The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in version…

Fix: after 4.5.4
Fix from $1,600 2024-10-25
Order Notification For Telegram MEDIUM 5.3
CVE-2024-9686

The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the …

Fix: after 1.0.1
Fix from $1,600 2024-10-25
Zimaos HIGH 7.5
CVE-2024-49357EPSS 24%

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpo…

Fix: 1.2.5+
Fix from $1,950 2024-10-24
Zimaos MEDIUM 5.3
CVE-2024-48932

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http://<Ser…

Fix: 1.2.5+
Fix from $1,600 2024-10-24
Unclassified CRITICAL 9.8
CVE-2024-48538

Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzi…

Mitigation only
Fix from $2,300 2024-10-24
Unclassified MEDIUM 5.3
CVE-2024-49683

Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp allows Accessing Functionali…

Mitigation only
Fix from $1,600 2024-10-24
Unclassified HIGH 7.7
CVE-2024-49657

Missing Authorization vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Exploiting Incorrectly Configured Access…

Mitigation only
Fix from $1,950 2024-10-23
Responsive Lightbox CRITICAL 9.8
CVE-2024-43924

Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect…

Fix: 2.4.8+
Fix from $2,300 2024-10-23
Rss Aggregator MEDIUM 5.4
CVE-2024-9583

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality d…

Fix: 4.23.13+
Fix from $1,600 2024-10-23