Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Eclipse Dataspace Components MEDIUM 5.3
CVE-2024-9202

In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a re…

Fix: 0.9.1+
Fix from $1,600 2024-09-27
Sight MEDIUM 5.3
CVE-2024-9025

The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch…

Fix: 1.1.3+
Fix from $1,600 2024-09-26
Slider HIGH 8.8
CVE-2024-47330

Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsys…

Fix: 1.8.7+
Fix from $1,950 2024-09-26
Revolut Gateway For Woocommerce MEDIUM 5.3
CVE-2024-8678

The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Fix: 4.17.4+
Fix from $1,600 2024-09-25
Chatbot With Chatgpt MEDIUM 5.3
CVE-2024-6845

The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users…

Fix: 2.4.6+
Fix from $1,600 2024-09-25
Mycred MEDIUM 5.3
CVE-2024-8658

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooComm…

Fix: 2.7.4+
Fix from $1,600 2024-09-25
Uncanny Groups For Learndash HIGH 7.2
CVE-2024-8349

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is du…

Fix: 6.1.1+
Fix from $1,950 2024-09-25
Mautic MEDIUM 6.5
CVE-2022-25768

The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. …

Fix: 4.4.13 / 5.1.1+
Fix from $1,600 2024-09-18
Unclassified HIGH 8.5
CVE-2024-6406

Missing Authentication for Critical Function, Missing Authorization vulnerability in Yordam Information Technology Mobile Library Application allows …

Mitigation only
Fix from $1,950 2024-09-18
Ipados MEDIUM 5.3
CVE-2024-40852

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to s…

Fix: 18.0+
Fix from $1,600 2024-09-17
GitLab HIGH 7.5
CVE-2024-4660

An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all…

Fix: 17.1.7 / 17.2.5+
Fix from $1,950 2024-09-12
Soliclub HIGH 7.5
CVE-2024-3305

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensiti…

Fix: 4.4.0 / 5.2.1+
Fix from $1,950 2024-09-12
Html5 Video Player MEDIUM 5.3
CVE-2024-7727

The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil…

Fix: 2.5.33+
Fix from $1,600 2024-09-11
Android HIGH 7.8
CVE-2024-40650

In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of p…

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-40652

In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing pe…

Patch available
Fix from $1,950 2024-09-11
Xwiki MEDIUM 5.3
CVE-2024-45591

XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed in…

Fix: 15.10.9 / 16.3.0+
Fix from $1,600 2024-09-10
Computer Vision Annotation Tool MEDIUM 6.4
CVE-2024-45393

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can acc…

Fix: 2.18.0+
Fix from $1,600 2024-09-10
Eventprime MEDIUM 5.3
CVE-2024-8369

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected eve…

Fix: 4.0.4.4+
Fix from $1,600 2024-09-10
Unclassified MEDIUM 5.4
CVE-2024-45285

The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. By s…

Mitigation only
Fix from $1,600 2024-09-10
Unclassified MEDIUM 5.4
CVE-2024-44117

The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and…

Mitigation only
Fix from $1,600 2024-09-10
Unclassified MEDIUM 6.5
CVE-2024-45286

Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting …

Mitigation only
Fix from $1,600 2024-09-10
Unclassified MEDIUM 5.4
CVE-2024-42371

The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to …

Mitigation only
Fix from $1,600 2024-09-10
Unclassified HIGH 7.8
CVE-2024-40709

A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.

Mitigation only
Fix from $1,950 2024-09-07
Qts HIGH 7.8
CVE-2023-39298

A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…

Mitigation only
Fix from $1,950 2024-09-06
Dir 823g Firmware HIGH 7.5
CVE-2024-44408

D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the down…

No fix yet
Fix from $1,950 2024-09-06
Accord Ors HIGH 7.5
CVE-2024-1744

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive…

Fix: 7.3.2.1+
Fix from $1,950 2024-09-06
Sirv HIGH 8.8
CVE-2024-8480

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check…

Fix: 7.2.8+
Fix from $1,950 2024-09-06
Geo Controller MEDIUM 5.3
CVE-2024-7381

The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the a…

Fix: after 8.6.9
Fix from $1,600 2024-09-05
Amelia MEDIUM 6.5
CVE-2024-6332

The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to…

Fix: after 7.7
Fix from $1,600 2024-09-05
Form Vibes MEDIUM 5.4
CVE-2024-5309

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missi…

Fix: 1.4.13+
Fix from $1,600 2024-09-05