Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Process Manufacturing Product Development HIGH 8.1
CVE-2024-21250

Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). …

Mitigation only
Fix from $1,950 2024-10-15
Product Hub HIGH 8.1
CVE-2024-21252

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.…

Fix: after 12.2.13
Fix from $1,950 2024-10-15
Bi Publisher HIGH 8.8
CVE-2024-21254

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.…

Mitigation only
Fix from $1,950 2024-10-15
Service Bus HIGH 7.5
CVE-2024-21246

Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version that is affe…

Mitigation only
Fix from $1,950 2024-10-15
Weblogic Server HIGH 7.5
CVE-2024-21234

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $1,950 2024-10-15
Fusion Middleware HIGH 7.5
CVE-2024-21215

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $1,950 2024-10-15
Weblogic Server CRITICAL 9.8
CVE-2024-21216

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $2,300 2024-10-15
Splunk MEDIUM 6.5
CVE-2024-45732

In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2…

Fix: 9.1.2308.208 / 9.1.2312.110+
Fix from $1,600 2024-10-14
Unclassified MEDIUM 5.4
CVE-2024-9860

The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'imp…

Mitigation only
Fix from $1,600 2024-10-12
Hunk Companion CRITICAL 9.8
CVE-2024-9707EPSS 9%

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-jso…

Fix: 1.8.5+
Fix from $2,300 2024-10-11
Linkz.ai MEDIUM 5.3
CVE-2024-9586

The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_auth' and 'check…

Fix: 1.2.0+
Fix from $1,600 2024-10-11
Unclassified CRITICAL 9.8
CVE-2024-9234EPSS 10%

The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads d…

Mitigation only
Fix from $2,300 2024-10-11
Youtrack MEDIUM 5.4
CVE-2024-48902

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API

Fix: 2024.3.46677+
Fix from $1,600 2024-10-10
Userplus MEDIUM 5.4
CVE-2024-9520

The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple …

Fix: after 2.0
Fix from $1,600 2024-10-10
Wp Helper Premium MEDIUM 5.3
CVE-2024-9065

The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send…

Fix: after 4.6.1
Fix from $1,600 2024-10-10
Qa Analytics MEDIUM 5.3
CVE-2024-8513

The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable to unauthorized modification…

Fix: after 4.1.0.0
Fix from $1,600 2024-10-10
3scale Api Management Platform MEDIUM 5.3
CVE-2024-9671

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invo…

Mitigation only
Fix from $1,600 2024-10-09
Unclassified MEDIUM 5.0
CVE-2024-42934

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with…

Mitigation only
Fix from $1,600 2024-10-09
Azure Stack Hci HIGH 8.8
CVE-2024-38179

Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2024-10-08
Seo MEDIUM 6.5
CVE-2024-9161

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a m…

Fix: 1.0.229+
Fix from $1,600 2024-10-05
Lif Authentication Server HIGH 8.1
CVE-2024-47768

Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery …

Fix: 1.7.3+
Fix from $1,950 2024-10-04
Unclassified HIGH 8.7
CVE-2024-47790

** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-Time Streaming Protocol (RTSP…

Mitigation only
Fix from $1,950 2024-10-04
Nexus Dashboard MEDIUM 5.4
CVE-2024-20477

A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files…

Fix: 3.2 / 12.2.2+
Fix from $1,600 2024-10-02
Nexus Dashboard MEDIUM 5.4
CVE-2024-20442

A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited A…

Fix: 3.2+
Fix from $1,600 2024-10-02
Nexus Dashboard MEDIUM 5.4
CVE-2024-20438

A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an af…

Fix: 3.2 / 12.2.2+
Fix from $1,600 2024-10-02
Unclassified MEDIUM 5.3
CVE-2024-8430

The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starte…

Mitigation only
Fix from $1,600 2024-10-01
Kb Support HIGH 8.1
CVE-2024-8548

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a mis…

Fix: 1.6.7+
Fix from $1,950 2024-10-01
Kb Support MEDIUM 6.5
CVE-2024-8632

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a m…

Fix: 1.6.7+
Fix from $1,600 2024-10-01
Railway Reservation System MEDIUM 6.3
CVE-2024-9297

A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Affected by this vulnerability i…

No fix yet
Fix from $1,600 2024-09-28
Eu\/uk Vat Manager For Woocommerce MEDIUM 5.3
CVE-2024-9189

The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th…

Fix: 2.12.14+
Fix from $1,600 2024-09-28