Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Lunary MEDIUM 5.4
CVE-2024-5127

In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and…

Fix: 1.2.25+
Fix from $1,600 2024-06-06
Wp Recall MEDIUM 5.3
CVE-2024-1175

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ch…

Fix: 16.26.6+
Fix from $1,600 2024-06-06
Buddypress Members Only MEDIUM 5.3
CVE-2024-0972

The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the …

Fix: after 3.3.5
Fix from $1,600 2024-06-06
Countdown Builder MEDIUM 5.4
CVE-2024-2017

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability che…

Fix: 2.7.8.1+
Fix from $1,600 2024-06-06
Login\/signup Popup HIGH 8.8
CVE-2024-5324

Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check o…

Fix: 2.6.1 / 2.6.2+
Fix from $1,950 2024-06-06
The Moneytizer HIGH 8.1
CVE-2023-6966

The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capabil…

Fix: 10.0.1+
Fix from $1,950 2024-06-06
Unlimited Elements For Elementor HIGH 8.8
CVE-2024-35674

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-e…

Fix: 1.5.110+
Fix from $1,950 2024-06-05
Powerbank HIGH 7.5
CVE-2024-1662

Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint Stock Company PowerBank Applic…

Fix: 2.02+
Fix from $1,950 2024-06-05
Spiffy Calendar MEDIUM 6.3
CVE-2024-30528

Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.

Fix: 4.9.11+
Fix from $1,600 2024-06-04
Chuanhuchatgpt HIGH 7.5
CVE-2024-4520

An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability a…

Fix: after 20240410
Fix from $1,950 2024-06-04
Move Addons For Elementor HIGH 7.3
CVE-2024-30525

Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9.

Fix: 1.3.0+
Fix from $1,950 2024-06-04
Netgsm CRITICAL 9.8
CVE-2024-35672

Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19.

Fix: after 2.9.16
Fix from $2,300 2024-06-04
Rt Easy Builder HIGH 8.8
CVE-2024-30484

Missing Authorization vulnerability in RT Easy Builder – Advanced addons for Elementor.This issue affects RT Easy Builder – Advanced addons for Eleme…

Fix: 2.1+
Fix from $1,950 2024-06-04
Unclassified MEDIUM 5.3
CVE-2024-4997

The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links for posts and pages in all v…

Mitigation only
Fix from $1,600 2024-06-04
Unclassified HIGH 7.2
CVE-2024-3555

The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to unauthorized access due to a mi…

Mitigation only
Fix from $1,950 2024-06-04
Cp Contact Form With Paypal HIGH 8.8
CVE-2023-27460

Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Fo…

Fix: 1.3.35+
Fix from $1,950 2024-06-03
Unclassified HIGH 7.3
CVE-2024-3821

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unauthorized access due to a miss…

Mitigation only
Fix from $1,950 2024-06-01
Unclassified HIGH 7.1
CVE-2024-4958

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized mo…

Mitigation only
Fix from $1,950 2024-06-01
Unclassified MEDIUM 5.3
CVE-2024-1324

The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the save_remote_i…

Mitigation only
Fix from $1,600 2024-06-01
Unclassified CRITICAL 9.8
CVE-2024-36246

Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with Local…

Mitigation only
Fix from $2,300 2024-05-31
Unclassified HIGH 8.8
CVE-2024-5326

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a mis…

Mitigation only
Fix from $1,950 2024-05-30
Comparison Slider MEDIUM 5.4
CVE-2024-4422

The Comparison Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider title parameter in all versions up to, and inc…

Fix: after 1.0.5
Fix from $1,600 2024-05-30
Unclassified MEDIUM 5.0
CVE-2024-3277

The Yumpu ePaper publishing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_han…

Mitigation only
Fix from $1,600 2024-05-30
Teamcity HIGH 8.1
CVE-2024-36377

In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

Fix: 2024.03.2+
Fix from $1,950 2024-05-29
Pe6208 Firmware MEDIUM 5.3
CVE-2023-43846

Incorrect access control in logs management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote attackers to get the device lo…

Fix: 2.4.239+
Fix from $1,600 2024-05-28
Unclassified HIGH 7.5
CVE-2024-35237

MIT IdentiBot is an open-source Discord bot written in Node.js that verifies individuals' affiliations with MIT, grants them roles in a Discord serve…

Patch available
Fix from $1,950 2024-05-27
Testimonial Carousel For Elementor MEDIUM 5.3
CVE-2024-4858

The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t…

Fix: 10.2.1+
Fix from $1,600 2024-05-25
GitLab MEDIUM 5.3
CVE-2024-5318

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and s…

Fix: 16.10.6 / 16.11.3+
Fix from $1,600 2024-05-24
Unclassified MEDIUM 5.3
CVE-2023-6325

The RomethemeForm For Elementor plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check …

Mitigation only
Fix from $1,600 2024-05-23
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2024-20355

A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Soft…

Mitigation only
Fix from $1,600 2024-05-22