Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.3
CVE-2024-41624

Incorrect access control in Himalaya Xiaoya nano smart speaker rom_version 1.6.96 allows a remote attacker to have an unspecified impact.

Mitigation only
Fix from $1,600 2024-07-29
Woocommerce Product Table MEDIUM 6.4
CVE-2024-6458

The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on th…

Fix: 3.8.6+
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.8
CVE-2024-6591

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check…

Mitigation only
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.4
CVE-2024-4410

The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is d…

Mitigation only
Fix from $1,600 2024-07-27
Tutor Lms Migration Tool MEDIUM 5.3
CVE-2024-1798

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_ex…

Fix: after 2.2.2
Fix from $1,600 2024-07-27
Wp Easypay MEDIUM 6.5
CVE-2024-5861

The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the…

Fix: 4.2.4+
Fix from $1,600 2024-07-24
Social Auto Poster MEDIUM 5.3
CVE-2024-6755

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw…

Fix: 5.3.15+
Fix from $1,600 2024-07-24
Social Auto Poster HIGH 7.5
CVE-2024-6750

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on…

Fix: 5.3.15+
Fix from $1,950 2024-07-24
Veristand CRITICAL 9.8
CVE-2024-6806

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remo…

Fix: after 2024
Fix from $2,300 2024-07-22
Veristand CRITICAL 9.8
CVE-2024-6805

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result i…

Fix: after 2024
Fix from $2,300 2024-07-22
Woocommerce Social Login CRITICAL 9.8
CVE-2024-6636

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_…

Fix: 2.7.4+
Fix from $2,300 2024-07-20
Getwid MEDIUM 5.3
CVE-2024-6489

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_go…

Fix: after 2.0.10
Fix from $1,600 2024-07-20
Artplacer Widget MEDIUM 6.5
CVE-2023-7268

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated user…

Fix: after 2.21.1
Fix from $1,600 2024-07-19
Elements Kit Elementor Addons MEDIUM 5.3
CVE-2024-6455

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a miss…

Fix: 3.2.1+
Fix from $1,600 2024-07-18
Unclassified MEDIUM 5.4
CVE-2024-6175

The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c…

Mitigation only
Fix from $1,600 2024-07-18
Bookingpress HIGH 8.8
CVE-2024-6660

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized modification o…

Fix: 1.1.6+
Fix from $1,950 2024-07-17
Brizy MEDIUM 6.5
CVE-2024-1937

The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_ite…

Fix: 2.4.45+
Fix from $1,600 2024-07-16
Unclassified MEDIUM 6.5
CVE-2024-37202

Missing Authorization vulnerability in BinaryCarpenter Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter custom-add-to-ca…

Mitigation only
Fix from $1,600 2024-07-12
Mstore Api CRITICAL 9.8
CVE-2024-6328

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and…

Fix: 4.15.0+
Fix from $2,300 2024-07-12
Sirv MEDIUM 5.4
CVE-2024-6392

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability…

Fix: 7.2.8+
Fix from $1,600 2024-07-11
Junos Os Evolved HIGH 7.3
CVE-2024-39546

A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticate…

Mitigation only
Fix from $1,950 2024-07-11
Payment Gateway MEDIUM 5.3
CVE-2024-0619

The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the payment_…

Fix: after 2.5.0
Fix from $1,600 2024-07-11
Codimd MEDIUM 5.3
CVE-2024-38353

CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability …

Fix: 2.5.4+
Fix from $1,600 2024-07-10
Windows 10 1809 HIGH 8.8
CVE-2024-21417

Windows Text Services Framework Elevation of Privilege Vulnerability

Fix: 10.0.17763.6054 / 10.0.19044.4651+
Fix from $1,950 2024-07-10
Android HIGH 7.8
CVE-2024-31318

In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. …

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31332

In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. This could …

Patch available
Fix from $1,950 2024-07-09
Unclassified HIGH 8.8
CVE-2024-6069

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for…

Mitigation only
Fix from $1,950 2024-07-09
Unclassified MEDIUM 6.5
CVE-2024-5992

The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_chatbo…

Mitigation only
Fix from $1,600 2024-07-09
Unclassified MEDIUM 5.4
CVE-2024-5993

The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_sessio…

Mitigation only
Fix from $1,600 2024-07-09
Unclassified MEDIUM 5.4
CVE-2024-5648

The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several func…

Mitigation only
Fix from $1,600 2024-07-09