Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Product Catalog Mode For Woocommerce CRITICAL 9.1
CVE-2024-25929

Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX.This issue affects Product Catalog Enquir…

Fix: 5.0.6+
Fix from $2,300 2024-06-09
Updraftplus Extension HIGH 8.8
CVE-2023-23640

Missing Authorization vulnerability in MainWP MainWP UpdraftPlus Extension.This issue affects MainWP UpdraftPlus Extension: from n/a through 4.0.6.

Fix: 4.0.7+
Fix from $1,950 2024-06-09
Unlimited Elements For Elementor HIGH 8.8
CVE-2023-31080

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlim…

Fix: 1.5.66+
Fix from $1,950 2024-06-09
Staging Extension HIGH 8.8
CVE-2023-23639

Missing Authorization vulnerability in MainWP MainWP Staging Extension.This issue affects MainWP Staging Extension: from n/a through 4.0.3.

Fix: 4.0.4+
Fix from $1,950 2024-06-09
New Order Notification For Woocommerce HIGH 8.8
CVE-2024-31098

Missing Authorization vulnerability in Mr.Ebabi New Order Notification for Woocommerce.This issue affects New Order Notification for Woocommerce: fro…

Fix: after 2.0.2
Fix from $1,950 2024-06-09
Postx HIGH 8.8
CVE-2024-31246

Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

Fix: 3.2.4+
Fix from $1,950 2024-06-09
Wp Sort Order HIGH 8.8
CVE-2024-31294

Missing Authorization vulnerability in Fahad Mahmood WP Sort Order.This issue affects WP Sort Order: from n/a through 1.3.1.

Fix: 1.3.2+
Fix from $1,950 2024-06-09
Wpc Badge Management For Woocommerce HIGH 8.8
CVE-2024-30537

Missing Authorization vulnerability in WPClever WPC Badge Management for WooCommerce.This issue affects WPC Badge Management for WooCommerce: from n/…

Fix: 2.4.1+
Fix from $1,950 2024-06-09
Delucks Seo CRITICAL 9.8
CVE-2024-30538

Missing Authorization vulnerability in DELUCKS GmbH DELUCKS SEO.This issue affects DELUCKS SEO: from n/a through 2.5.4.

Fix: 2.5.5+
Fix from $2,300 2024-06-09
Awesome Support CRITICAL 9.8
CVE-2024-30539

Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.

Fix: 6.1.8+
Fix from $2,300 2024-06-09
Booster For Woocommerce MEDIUM 6.5
CVE-2023-52230

Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1…

Fix: after 7.1.3
Fix from $1,600 2024-06-09
Booster For Woocommerce MEDIUM 6.5
CVE-2023-52232

Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1…

Fix: 7.1.2+
Fix from $1,600 2024-06-09
Calendarista CRITICAL 9.8
CVE-2024-30534

Missing Authorization vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: fro…

Fix: 3.0.6+
Fix from $2,300 2024-06-09
Product Vendors CRITICAL 9.8
CVE-2023-51494

Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1.

Fix: 2.2.2+
Fix from $2,300 2024-06-09
Icegram Express MEDIUM 5.4
CVE-2024-21748

Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.

Fix: 3.1.22+
Fix from $1,600 2024-06-08
Import And Export Users And Customers MEDIUM 5.3
CVE-2024-22151

Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from…

Fix: 1.24.7+
Fix from $1,600 2024-06-08
Kivicare HIGH 8.8
CVE-2024-35659

Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Contr…

Fix: after 3.6.4
Fix from $1,950 2024-06-08
Cf7 Google Sheets Connector MEDIUM 6.5
CVE-2024-5654

The CF7 Google Sheets Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'exe…

Fix: 5.0.10+
Fix from $1,600 2024-06-08
Salon Booking System MEDIUM 5.4
CVE-2024-4468

The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on seve…

Fix: 10.0+
Fix from $1,600 2024-06-08
Minimal Coming Soon \& Maintenance Mode MEDIUM 5.4
CVE-2024-5087

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Fix: 2.39+
Fix from $1,600 2024-06-08
Master Addons MEDIUM 5.3
CVE-2024-5382

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to unauthorized modi…

Fix: 2.0.6.2+
Fix from $1,600 2024-06-07
Market Exporter HIGH 8.1
CVE-2024-5637

The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_files' function …

Fix: 2.0.20+
Fix from $1,950 2024-06-07
Gdpr Ccpa Compliance \& Cookie Consent Banner MEDIUM 5.4
CVE-2024-5607

The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Fix: 2.7.1+
Fix from $1,600 2024-06-07
Clever Fox MEDIUM 5.4
CVE-2023-6876

The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Fix: 25.2.1+
Fix from $1,600 2024-06-07
Lunary MEDIUM 6.5
CVE-2024-5248

In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` en…

Fix: 1.4.9+
Fix from $1,600 2024-06-06
Lunary MEDIUM 6.5
CVE-2024-5126

An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating…

Fix: 1.2.25+
Fix from $1,600 2024-06-06
Lunary HIGH 8.2
CVE-2024-5129

A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization ch…

Fix: 1.2.8+
Fix from $1,950 2024-06-06
Lunary HIGH 7.5
CVE-2024-5130

An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete …

Fix: 1.2.8+
Fix from $1,950 2024-06-06
Litellm HIGH 8.1
CVE-2024-4888

BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on the `/audio/transcriptions` en…

Fix: 1.35.19+
Fix from $1,950 2024-06-06
Zenml MEDIUM 6.5
CVE-2024-2035

An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vuln…

Fix: 0.56.2+
Fix from $1,600 2024-06-06