Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Download Plugin MEDIUM 6.5
CVE-2024-9829

The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_downloa…

Fix: 2.2.1+
Fix from $1,600 2024-10-23
Digital Experience Platform HIGH 8.8
CVE-2024-38002

The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th…

Fix: 7.4.3.112 / 2023.q3.9+
Fix from $1,950 2024-10-22
Rover Idx MEDIUM 6.3
CVE-2024-10003

The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple…

Fix: 3.0.0.2905+
Fix from $1,600 2024-10-22
Unclassified HIGH 7.5
CVE-2024-48645

In Minecraft mod "Command Block IDE" up to and including version 0.4.9, a missing authorization (CWE-862) allows any user to modify "function" files …

Patch available
Fix from $1,950 2024-10-21
Nginx Ui HIGH 7.5
CVE-2024-49367

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be…

Fix: after 1.9.9-4
Fix from $1,950 2024-10-21
Profilegrid MEDIUM 6.5
CVE-2024-49273

Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects ProfileGrid : from …

Fix: after 5.9.3
Fix from $1,600 2024-10-21
Wp Vr MEDIUM 5.4
CVE-2024-49293

Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

Fix: after 8.5.4
Fix from $1,600 2024-10-21
Photo Gallery Builder HIGH 8.8
CVE-2024-49325

Missing Authorization vulnerability in wpdiscover Photo Gallery Builder photo-gallery-builder allows Accessing Functionality Not Properly Constrained…

Fix: after 3.0
Fix from $1,950 2024-10-20
Wp Easy Post Types MEDIUM 6.3
CVE-2024-10078

The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on…

Fix: after 1.4.4
Fix from $1,600 2024-10-18
Ata 191 Firmware HIGH 7.1
CVE-2024-20463

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remot…

Fix: 11.2.5 / 12.0.2+
Fix from $1,950 2024-10-16
Cloudstack MEDIUM 6.3
CVE-2024-45461

The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. …

Fix: 4.18.2.4 / 4.19.1.2+
Fix from $1,600 2024-10-16
Timetable And Event Schedule CRITICAL 9.8
CVE-2020-36840

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_…

Fix: 2.3.9+
Fix from $2,300 2024-10-16
Paytium MEDIUM 6.5
CVE-2023-7294

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check …

Fix: 4.4.0+
Fix from $1,600 2024-10-16
Paytium HIGH 8.1
CVE-2023-7291

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che…

Fix: 4.4.0+
Fix from $1,950 2024-10-16
Paytium MEDIUM 5.4
CVE-2023-7287

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capabilit…

Fix: 4.4.0+
Fix from $1,600 2024-10-16
Download Monitor HIGH 7.5
CVE-2022-4972

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related …

Fix: after 4.7.51
Fix from $1,950 2024-10-16
Unclassified MEDIUM 6.3
CVE-2022-4974

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosu…

Mitigation only
Fix from $1,600 2024-10-16
Essential Addons For Elementor HIGH 8.8
CVE-2021-4447

The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of…

Fix: 4.6.5+
Fix from $1,950 2024-10-16
Kaswara CRITICAL 9.8
CVE-2021-4448

The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient c…

Fix: after 3.0.1
Fix from $2,300 2024-10-16
Unclassified HIGH 7.3
CVE-2021-4444

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing autho…

Mitigation only
Fix from $1,950 2024-10-16
Unclassified MEDIUM 6.3
CVE-2020-36834

The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and includ…

Mitigation only
Fix from $1,600 2024-10-16
Migration\, Backup\, Staging MEDIUM 6.5
CVE-2020-36835

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to…

Fix: 0.9.36+
Fix from $1,600 2024-10-16
Unclassified CRITICAL 9.9
CVE-2020-36837

The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_action…

Mitigation only
Fix from $2,300 2024-10-16
Speed Optimizer CRITICAL 9.8
CVE-2019-25217

The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in vers…

Fix: 5.0.12+
Fix from $2,300 2024-10-16
Social Networks Auto Poster MEDIUM 6.5
CVE-2020-36831

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple …

Fix: 4.3.18+
Fix from $1,600 2024-10-16
Unclassified MEDIUM 6.3
CVE-2020-36833

The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in vers…

Mitigation only
Fix from $1,600 2024-10-16
Shopwp MEDIUM 6.1
CVE-2019-25214

The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to,…

Fix: after 2.0.4
Fix from $1,600 2024-10-16
Ari Adminer HIGH 7.3
CVE-2019-25215

The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin i…

Fix: after 1.1.14
Fix from $1,950 2024-10-16
File Manager CRITICAL 9.8
CVE-2018-25105

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions …

Fix: after 3.0
Fix from $2,300 2024-10-16
Power Platform HIGH 8.6
CVE-2024-38190

Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.

Patch available
Fix from $1,950 2024-10-15