Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 6.4
CVE-2024-5669

The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthorized modification of data due…

Mitigation only
Fix from $1,600 2024-07-09
Unclassified MEDIUM 5.4
CVE-2024-5600

The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing …

No fix yet
Fix from $1,600 2024-07-09
Unclassified MEDIUM 5.3
CVE-2024-3608

The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_d…

Mitigation only
Fix from $1,600 2024-07-09
Unclassified MEDIUM 5.4
CVE-2024-4102

The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all v…

Mitigation only
Fix from $1,600 2024-07-09
Unclassified HIGH 7.2
CVE-2024-6180

The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings…

Mitigation only
Fix from $1,950 2024-07-09
S4core MEDIUM 5.4
CVE-2024-37172

SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation o…

Mitigation only
Fix from $1,600 2024-07-09
Customer Relationship Management S4fnd MEDIUM 6.5
CVE-2024-37175

SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow a…

Mitigation only
Fix from $1,600 2024-07-09
S4core MEDIUM 6.5
CVE-2024-39592

Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an …

Mitigation only
Fix from $1,600 2024-07-09
Extreme Xds MEDIUM 6.5
CVE-2024-4341

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by U…

Fix: 3928+
Fix from $1,600 2024-07-08
Gallery MEDIUM 6.3
CVE-2024-37542

Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: f…

Fix: after 2.0.3
Fix from $1,600 2024-07-06
Mastodon HIGH 8.2
CVE-2024-37903

Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific …

Fix: 4.1.18 / 4.2.10+
Fix from $1,950 2024-07-05
One Click Order Re Order MEDIUM 5.4
CVE-2024-5641

The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_oc…

Fix: 1.1.10+
Fix from $1,600 2024-07-04
Discourse MEDIUM 6.5
CVE-2024-36113

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version…

Fix: 3.2.3 / 3.3.0+
Fix from $1,600 2024-07-03
Learnpress MEDIUM 5.3
CVE-2024-6088

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the '…

Fix: 4.2.6.8.2+
Fix from $1,600 2024-07-02
Motors Car Dealer\, Classifieds \& Listing MEDIUM 5.3
CVE-2024-5545

The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch…

Fix: 1.4.11+
Fix from $1,600 2024-07-02
MongoDB MEDIUM 6.5
CVE-2024-6375

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to ei…

Fix: 5.0.22 / 6.0.11+
Fix from $1,600 2024-07-01
Simple Photoswipe MEDIUM 6.5
CVE-2024-5570

The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated …

Fix: after 0.1
Fix from $1,600 2024-06-28
Unclassified MEDIUM 5.4
CVE-2024-5863

The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_image_collage() …

Mitigation only
Fix from $1,600 2024-06-28
Unclassified CRITICAL 10.0
CVE-2024-6071

PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS command…

Mitigation only
Fix from $2,300 2024-06-27
Devika HIGH 8.8
CVE-2024-5820

An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend a…

No fix yet
Fix from $1,950 2024-06-27
Litellm MEDIUM 6.5
CVE-2024-5710

berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to…

No fix yet
Fix from $1,600 2024-06-27
Unclassified CRITICAL 9.3
CVE-2024-2882

SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. This breach could potentially …

Mitigation only
Fix from $2,300 2024-06-27
Conduit HIGH 8.8
CVE-2024-6303

Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for …

Fix: 0.8.0+
Fix from $1,950 2024-06-25
Wishlist Member X HIGH 7.5
CVE-2024-37111

Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

Fix: after 3.26.7
Fix from $1,950 2024-06-24
Sparkle Demo Importer MEDIUM 6.5
CVE-2024-6120

The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on…

Fix: 1.4.8+
Fix from $1,600 2024-06-22
Gutenberg Forms HIGH 8.8
CVE-2022-45803

Missing Authorization vulnerability in Nikolay Strikhar WordPress Form Builder Plugin – Gutenberg Forms.This issue affects WordPress Form Builder Plu…

Fix: 2.2.9+
Fix from $1,950 2024-06-21
Embedpress HIGH 8.8
CVE-2023-51375

Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.

Fix: 3.8.4+
Fix from $1,950 2024-06-21
Wp Tools HIGH 8.8
CVE-2022-43453

Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41.

Fix: 3.43+
Fix from $1,950 2024-06-21
Convertkit Email Marketing\, Email Newsletter And Landing Pages MEDIUM 5.3
CVE-2024-3961

The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of …

Fix: 2.4.9.1+
Fix from $1,600 2024-06-21
License Manager For Woocommerce MEDIUM 6.5
CVE-2024-1639

The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLi…

Fix: after 3.0.7
Fix from $1,600 2024-06-21