Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 8.8
CVE-2024-43247

Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WHMpres…

Mitigation only
Fix from $1,950 2024-08-19
Xwiki HIGH 8.0
CVE-2024-43401

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can …

Fix: after 15.9
Fix from $1,950 2024-08-19
Pi Hole HIGH 7.5
CVE-2024-44069

Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier rep…

Fix: 6.0+
Fix from $1,950 2024-08-19
Unclassified MEDIUM 5.3
CVE-2024-35686

Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through…

Mitigation only
Fix from $1,600 2024-08-18
Unclassified MEDIUM 5.3
CVE-2023-4730

The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function …

Mitigation only
Fix from $1,600 2024-08-17
Radio Player MEDIUM 5.3
CVE-2023-4024

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player funct…

Fix: 2.0.74+
Fix from $1,600 2024-08-17
Radio Player MEDIUM 5.3
CVE-2023-4025

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player funct…

Fix: 2.0.74+
Fix from $1,600 2024-08-17
Radio Player MEDIUM 5.3
CVE-2023-4027

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings fun…

Fix: after 2.0.73
Fix from $1,600 2024-08-17
Unclassified CRITICAL 10.0
CVE-2024-6500

The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capa…

Mitigation only
Fix from $2,300 2024-08-17
Unclassified HIGH 7.5
CVE-2024-38699

Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This i…

Mitigation only
Fix from $1,950 2024-08-13
Unclassified HIGH 7.5
CVE-2024-37935

Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects…

Mitigation only
Fix from $1,950 2024-08-13
Document Builder MEDIUM 5.3
CVE-2024-39591

SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing lo…

Mitigation only
Fix from $1,600 2024-08-13
Student Life Cycle Management MEDIUM 5.4
CVE-2024-42373

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of…

Mitigation only
Fix from $1,600 2024-08-13
Shared Service Framework MEDIUM 6.5
CVE-2024-42376

SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On succ…

Mitigation only
Fix from $1,600 2024-08-13
Business Objects Business Intelligence Platform CRITICAL 9.8
CVE-2024-41730EPSS 76%

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a lo…

Mitigation only
Fix from $2,300 2024-08-13
Netweaver Abap MEDIUM 6.3
CVE-2024-33005

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java)…

Mitigation only
Fix from $1,600 2024-08-13
Smartmag HIGH 7.5
CVE-2024-37930

Insertion of Sensitive Information into Log File vulnerability in ThemeSphere SmartMag smartmag-responsive-retina-wordpress-magazine.This issue affec…

Fix: after 9.3.0
Fix from $1,950 2024-08-12
Unclassified MEDIUM 5.4
CVE-2024-7621

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due …

Mitigation only
Fix from $1,600 2024-08-12
FreeBSD HIGH 7.5
CVE-2024-6760

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivile…

Fix: 13.0 / 13.3+
Fix from $1,950 2024-08-12
Openhab CRITICAL 9.1
CVE-2024-42470

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Several endpoints in versions …

Fix: 4.2.1+
Fix from $2,300 2024-08-12
Emui HIGH 7.8
CVE-2024-42035

Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confi…

No fix yet
Fix from $1,950 2024-08-08
Falang HIGH 7.1
CVE-2024-6869

The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on s…

Fix: 1.3.53+
Fix from $1,950 2024-08-08
Jenkins MEDIUM 6.3
CVE-2024-43045

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read perm…

Fix: 2.452.4 / 2.471+
Fix from $1,600 2024-08-07
Templatespare MEDIUM 5.4
CVE-2024-6872

The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for Elementor & Gutenberg Blocks!…

Fix: 2.4.3+
Fix from $1,600 2024-08-03
Filester HIGH 8.8
CVE-2024-7031

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt…

Fix: 1.8.3+
Fix from $1,950 2024-08-03
Fundengine HIGH 8.8
CVE-2024-6698

The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not …

Fix: 1.7.1+
Fix from $1,950 2024-08-01
Fogproject MEDIUM 5.9
CVE-2024-41108

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only …

Fix: 1.5.10.41+
Fix from $1,600 2024-07-31
Xwiki HIGH 8.8
CVE-2024-37901

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can per…

Fix: 14.10.21 / 15.5.5+
Fix from $1,950 2024-07-31
Tainacan MEDIUM 6.5
CVE-2024-7135

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all ve…

Fix: 0.21.8+
Fix from $1,600 2024-07-31
Unclassified MEDIUM 5.3
CVE-2024-2508

The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_menu_item_ic…

Mitigation only
Fix from $1,600 2024-07-31