Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Enjoy Social Feed HIGH 8.8
CVE-2024-0780

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing a…

Fix: after 6.2.2
Fix from $1,950 2024-03-18
Unclassified HIGH 8.2
CVE-2024-22257

In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6…

Mitigation only
Fix from $1,950 2024-03-18
Unclassified MEDIUM 5.3
CVE-2024-1857

The Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates plugin for WordPress is vulne…

Mitigation only
Fix from $1,600 2024-03-16
Word Replacer Pro MEDIUM 5.3
CVE-2024-1733

The Word Replacer Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the word_replacer_…

Mitigation only
Fix from $1,600 2024-03-16
Sirv HIGH 8.8
CVE-2023-50898

Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.

Fix: after 7.1.2
Fix from $1,950 2024-03-15
Zookeeper MEDIUM 5.3
CVE-2024-23944

Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by…

Fix: 3.8.4 / 3.9.2+
Fix from $1,600 2024-03-15
Woocommerce Add To Cart Custom Redirect MEDIUM 6.5
CVE-2024-1862

The WooCommerce Add to Cart Custom Redirect plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing…

Fix: 1.2.14+
Fix from $1,600 2024-03-13
Wp Social Login And Register Social Counter MEDIUM 5.3
CVE-2024-1763

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c…

Fix: after 3.0.0
Fix from $1,600 2024-03-13
Relevanssi MEDIUM 5.3
CVE-2024-1380EPSS 50%

The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanss…

Fix: 4.22.1+
Fix from $1,600 2024-03-13
Ht Easy Ga4 MEDIUM 5.3
CVE-2024-1176

The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili…

Fix: 1.2.0+
Fix from $1,600 2024-03-13
Play.ht MEDIUM 6.3
CVE-2024-0828

The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to unauthorized access of functionality du…

Fix: after 3.6.4
Fix from $1,600 2024-03-13
Bulgarisation For Woocommerce HIGH 7.5
CVE-2024-0683

The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in …

Fix: 3.0.15+
Fix from $1,950 2024-03-13
Lifterlms MEDIUM 5.3
CVE-2024-0377

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit…

Fix: 7.5.2+
Fix from $1,600 2024-03-13
Artibot MEDIUM 5.0
CVE-2024-0447

The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Fix: 1.1.7+
Fix from $1,600 2024-03-13
Download Manager MEDIUM 5.3
CVE-2023-6785

The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and includ…

Fix: 3.2.85+
Fix from $1,600 2024-03-13
Blossom Spa HIGH 7.5
CVE-2024-2107

The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.3 via generated source.…

Fix: 1.3.4+
Fix from $1,950 2024-03-12
Ladipage MEDIUM 5.4
CVE-2023-4728

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function ho…

Fix: after 4.4
Fix from $1,600 2024-03-12
Newsletter2go MEDIUM 5.4
CVE-2024-1328

The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 4…

Fix: 4.0.14+
Fix from $1,600 2024-03-12
Abap Platform MEDIUM 5.3
CVE-2024-27900

Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of jo…

Mitigation only
Fix from $1,600 2024-03-12
Eventprime MEDIUM 5.4
CVE-2024-1125

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ch…

Fix: 3.4.4+
Fix from $1,600 2024-03-09
Eventprime MEDIUM 6.5
CVE-2024-1123

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab…

Fix: 3.4.3+
Fix from $1,600 2024-03-09
Affiliate Toolkit MEDIUM 6.5
CVE-2024-1851

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the…

Fix: 3.5.5+
Fix from $1,600 2024-03-08
macOS MEDIUM 5.5
CVE-2024-23230

This issue was addressed with improved file handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app m…

Fix: 12.7.4 / 13.6.5+
Fix from $1,600 2024-03-08
Youtrack MEDIUM 6.5
CVE-2024-28230

In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

Fix: 2024.1.25893+
Fix from $1,600 2024-03-07
Post Form HIGH 8.2
CVE-2024-1170

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner…

Fix: 2.8.8+
Fix from $1,950 2024-03-07
Post Form HIGH 7.5
CVE-2024-1169

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner…

Fix: 2.8.8+
Fix from $1,950 2024-03-07
Ngrinder MEDIUM 5.4
CVE-2024-28216

nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of informa…

Fix: 3.5.9+
Fix from $1,600 2024-03-07
Ngrinder HIGH 7.5
CVE-2024-28215

nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of informa…

Fix: 3.5.9+
Fix from $1,950 2024-03-07
Docker Build Step HIGH 8.8
CVE-2024-2216

A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to …

Fix: after 2.11
Fix from $1,950 2024-03-06
Build \& Control Block Pattern MEDIUM 5.3
CVE-2024-1095

The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing cap…

Fix: after 1.3.5.4
Fix from $1,600 2024-03-05