Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 7.1
CVE-2024-45050

Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where Ringer…

Patch available
Fix from $1,950 2024-09-04
Multivendorx CRITICAL 9.8
CVE-2024-8289

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escalation/de-escalation…

Fix: 4.2.1+
Fix from $2,300 2024-09-04
Wp Extended HIGH 8.8
CVE-2024-8102

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e…

Fix: 3.0.9+
Fix from $1,950 2024-09-04
Wp Job Portal CRITICAL 9.8
CVE-2024-7950

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitr…

Fix: 2.1.7+
Fix from $2,300 2024-09-04
Sudobot CRITICAL 9.8
CVE-2024-45307

SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is …

Fix: 9.26.7+
Fix from $2,300 2024-09-03
Akos CRITICAL 9.8
CVE-2024-4259

Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatService) allows Collect Data as Pro…

Fix: after 2024-09-02
Fix from $2,300 2024-09-03
Media Library Folders MEDIUM 6.3
CVE-2024-7858

The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the…

Fix: 8.2.4+
Fix from $1,600 2024-08-30
Tutor Lms HIGH 7.1
CVE-2024-5784

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple…

Fix: 2.7.3+
Fix from $1,950 2024-08-30
Zynith MEDIUM 6.5
CVE-2024-43939

Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constrained by ACLs.This issue affe…

Fix: after 7.4.9
Fix from $1,600 2024-08-29
Zynith MEDIUM 6.5
CVE-2024-43940

Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constrained by ACLs.This issue affe…

Fix: after 7.4.9
Fix from $1,600 2024-08-29
Mp3 Audio Player For Music\, Radio \& Podcast HIGH 8.1
CVE-2024-7856EPSS 19%

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due …

Fix: 5.7.1+
Fix from $1,950 2024-08-29
Managment Portal CRITICAL 9.8
CVE-2024-4428

Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect…

Fix: after 21.05.2024
Fix from $2,300 2024-08-29
Funnelforms Free MEDIUM 5.3
CVE-2024-5857

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorize…

Fix: 3.7.4.1+
Fix from $1,600 2024-08-29
Ichiba MEDIUM 6.1
CVE-2024-41918

'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in h…

Fix: after 12.4.0
Fix from $1,600 2024-08-29
I Educar HIGH 8.1
CVE-2024-45058

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to…

Fix: after 2.9
Fix from $1,950 2024-08-28
Unclassified MEDIUM 6.7
CVE-2024-20413

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges t…

Mitigation only
Fix from $1,600 2024-08-28
Permalink Manager Lite MEDIUM 5.3
CVE-2024-8195

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', '…

Fix: 2.4.4.1+
Fix from $1,600 2024-08-28
Funnelforms Free MEDIUM 5.3
CVE-2024-7447

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorize…

Fix: 3.7.4.1+
Fix from $1,600 2024-08-28
Mycred MEDIUM 5.3
CVE-2024-43214

Missing Authorization vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

Fix: after 2.7.3
Fix from $1,600 2024-08-26
Woocommerce Google Feed Manager HIGH 8.8
CVE-2024-7258

The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_r…

Fix: 2.9.0+
Fix from $1,950 2024-08-23
Wp Sms CRITICAL 9.8
CVE-2024-43331

Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.

Fix: 6.9.4+
Fix from $2,300 2024-08-22
Idol2 CRITICAL 9.1
CVE-2024-45168

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism…

Fix: after 2.12
Fix from $2,300 2024-08-22
Wp Testimonial Widget MEDIUM 5.3
CVE-2024-7390

The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTest…

Fix: after 3.1
Fix from $1,600 2024-08-21
Smart Online Order For Clover MEDIUM 6.5
CVE-2024-7032

The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'moo_deact…

Fix: 1.5.7+
Fix from $1,600 2024-08-21
Spring Security HIGH 7.5
CVE-2024-38810

Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

Fix: 6.3.2+
Fix from $1,950 2024-08-20
Givewp MEDIUM 5.4
CVE-2024-5941

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing…

Fix: 3.14.2+
Fix from $1,600 2024-08-20
Givewp MEDIUM 5.3
CVE-2024-5939

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c…

Fix: 3.14.0+
Fix from $1,600 2024-08-20
Givewp MEDIUM 5.3
CVE-2024-5940

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi…

Fix: 3.14.0+
Fix from $1,600 2024-08-20
Unclassified MEDIUM 5.4
CVE-2024-43326

Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affe…

Mitigation only
Fix from $1,600 2024-08-19
Unclassified HIGH 7.1
CVE-2024-43256

Missing Authorization vulnerability in nouthemes Leopard - WordPress offload media allows Accessing Functionality Not Properly Constrained by ACLs.Th…

Mitigation only
Fix from $1,950 2024-08-19