Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 7.1
CVE-2024-31366

Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8.

Mitigation only
Fix from $1,950 2024-04-09
Unclassified MEDIUM 6.5
CVE-2024-28167

SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.…

Mitigation only
Fix from $1,600 2024-04-09
Ex200 Firmware HIGH 8.4
CVE-2024-31813

TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.

Mitigation only
Fix from $1,950 2024-04-08
Unclassified MEDIUM 5.4
CVE-2024-31375

Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a through <= 3.2.7.

Mitigation only
Fix from $1,600 2024-04-08
Emui HIGH 7.5
CVE-2023-52541

Authentication vulnerability in the API for app pre-loading. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2024-04-08
Android MEDIUM 5.5
CVE-2023-52352

In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution pri…

Mitigation only
Fix from $1,600 2024-04-08
Emui HIGH 7.7
CVE-2023-52713

Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect avail…

No fix yet
Fix from $1,950 2024-04-07
Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels MEDIUM 5.3
CVE-2024-3216

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of da…

Fix: 4.4.3+
Fix from $1,600 2024-04-06
Wp Stateless HIGH 7.1
CVE-2024-1385

The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the dism…

Fix: after 3.4.0
Fix from $1,950 2024-04-06
Unclassified MEDIUM 5.3
CVE-2024-27910

A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication.

Mitigation only
Fix from $1,600 2024-04-05
Unclassified HIGH 7.5
CVE-2024-27911

A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.

Mitigation only
Fix from $1,950 2024-04-05
Linux Kernel MEDIUM 5.5
CVE-2024-26705

In the Linux kernel, the following vulnerability has been resolved: parisc: BTLB: Fix crash when setting up BTLB at CPU bringup When using hotplug …

Fix: 6.6.18 / 6.7.6+
Fix from $1,600 2024-04-03
Unclassified HIGH 7.8
CVE-2024-0394

Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges a…

Mitigation only
Fix from $1,950 2024-04-03
Unclassified MEDIUM 6.5
CVE-2024-1807

The Product Sort and Display for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec…

Mitigation only
Fix from $1,600 2024-04-02
Unclassified MEDIUM 5.3
CVE-2024-1732

The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabili…

Mitigation only
Fix from $1,600 2024-04-02
Shortcodes And Extra Features For Phlox Theme HIGH 8.8
CVE-2024-31099

Missing Authorization vulnerability in Averta Shortcodes and extra features for Phlox theme auxin-elements.This issue affects Shortcodes and extra fe…

Fix: 2.15.8+
Fix from $1,950 2024-04-01
Unclassified CRITICAL 10.0
CVE-2024-2086

The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugi…

Mitigation only
Fix from $2,300 2024-03-30
Bear Woocommerce Bulk Editor And Products Manager Professional MEDIUM 5.3
CVE-2024-30463

Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.3.

Fix: 1.1.4.4+
Fix from $1,600 2024-03-29
Wholesale For Woocommerce MEDIUM 5.3
CVE-2024-30469

Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

Fix: 2.3.1+
Fix from $1,600 2024-03-29
Klarna For Woocommerce CRITICAL 9.8
CVE-2024-30477

Missing Authorization vulnerability in Klarna Klarna Payments for WooCommerce.This issue affects Klarna Payments for WooCommerce: from n/a through 3.…

Fix: after 3.2.4
Fix from $2,300 2024-03-29
Wp Hotel Booking CRITICAL 9.8
CVE-2024-30508

Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

Fix: 2.0.9.3+
Fix from $2,300 2024-03-29
Church Admin MEDIUM 6.5
CVE-2024-30505

Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.18.

Fix: 4.1.19+
Fix from $1,600 2024-03-29
Mp3 Audio Player For Music\, Radio \& Podcast HIGH 7.6
CVE-2024-30487

Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Mus…

Fix: 5.1.1+
Fix from $1,950 2024-03-29
Unclassified HIGH 7.5
CVE-2024-2848

The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_footer_text_callb…

Mitigation only
Fix from $1,950 2024-03-29
Ipados MEDIUM 5.5
CVE-2023-42896

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iP…

Fix: 12.7.2 / 13.6.3+
Fix from $1,600 2024-03-28
Surveillance Station CRITICAL 9.9
CVE-2024-29241

Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authe…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $2,300 2024-03-28
Surveillance Station HIGH 7.7
CVE-2024-29229

Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows rem…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,950 2024-03-28
Surveillance Station HIGH 7.7
CVE-2024-29228

Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remot…

Fix: 9.2.0-9289 / 9.2.0-11289+
Fix from $1,950 2024-03-28
Unclassified MEDIUM 5.4
CVE-2024-28003

Missing Authorization vulnerability in Megamenu Max Mega Menu.This issue affects Max Mega Menu: from n/a through 3.3.

Mitigation only
Fix from $1,600 2024-03-28
Unclassified MEDIUM 5.3
CVE-2024-2962

The Networker - Tech News WordPress Theme with Dark Mode theme for WordPress is vulnerable to unauthorized modification of data due to a missing capa…

Mitigation only
Fix from $1,600 2024-03-27