Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Application Licensing MEDIUM 5.3
CVE-2024-26138

The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the document `Licenses.Code.LicenseJSON`…

Fix: 1.24.2+
Fix from $1,600 2024-02-21
Simple Job Board MEDIUM 5.3
CVE-2024-0593

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick…

Fix: 2.11.0+
Fix from $1,600 2024-02-21
Woocommerce Google Sheet Connector MEDIUM 5.3
CVE-2024-1562

The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t…

Fix: 1.3.12+
Fix from $1,600 2024-02-21
Plugin Groups HIGH 8.2
CVE-2024-1108

The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() funct…

Fix: 2.0.7+
Fix from $1,950 2024-02-21
Android HIGH 7.8
CVE-2024-0038

In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission…

Patch available
Fix from $1,950 2024-02-16
Android MEDIUM 5.5
CVE-2023-40105

In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could le…

Patch available
Fix from $1,600 2024-02-15
Android MEDIUM 5.5
CVE-2023-40113

In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local…

Patch available
Fix from $1,600 2024-02-15
Collaboration MEDIUM 6.5
CVE-2023-26562

In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/s…

Mitigation only
Fix from $1,600 2024-02-13
Bank Account Management MEDIUM 6.3
CVE-2024-24739

SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges w…

Mitigation only
Fix from $1,600 2024-02-13
Awesome Support MEDIUM 5.3
CVE-2024-0596

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili…

Fix: 6.1.8+
Fix from $1,600 2024-02-10
Eventin MEDIUM 5.3
CVE-2024-1122

The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to…

Fix: 3.3.51+
Fix from $1,600 2024-02-09
GitLab MEDIUM 6.7
CVE-2023-6840

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allo…

Fix: 16.6.7 / 16.7.5+
Fix from $1,600 2024-02-07
Admin Classic Bundle CRITICAL 9.1
CVE-2024-24822

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags withou…

Fix: 1.3.3+
Fix from $2,300 2024-02-07
Podlove Podcast Publisher MEDIUM 5.3
CVE-2024-1110

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init()…

Fix: after 4.0.11
Fix from $1,600 2024-02-07
Podlove Podcast Publisher MEDIUM 5.3
CVE-2024-1109

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_downloa…

Fix: after 4.0.11
Fix from $1,600 2024-02-07
Quiz Maker MEDIUM 5.3
CVE-2024-1079

The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function…

Fix: 6.5.2.5+
Fix from $1,600 2024-02-07
Website Builder By Seedprod HIGH 7.5
CVE-2024-1072

The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unaut…

Fix: after 6.15.21
Fix from $1,950 2024-02-05
Advanced Forms For Acf MEDIUM 5.3
CVE-2024-1121

The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_json_fil…

Fix: after 1.9.3.2
Fix from $1,600 2024-02-05
Wp Club Manager MEDIUM 5.3
CVE-2024-1177

The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit…

Fix: 2.2.11+
Fix from $1,600 2024-02-05
Instant Images One Click Unsplash Uploads MEDIUM 6.5
CVE-2024-0869

The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrar…

Fix: after 6.1.0
Fix from $1,600 2024-02-05
Profile Builder HIGH 7.5
CVE-2024-0324

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized mod…

Fix: after 3.10.8
Fix from $1,950 2024-02-05
Ai Assistant HIGH 8.8
CVE-2023-6985

The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi…

Fix: 1.0.19+
Fix from $1,950 2024-02-05
Wp Gdpr Compliance HIGH 8.8
CVE-2023-6700

The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check …

Fix: after 2.0.22
Fix from $1,950 2024-02-05
Migration\, Backup\, Staging MEDIUM 5.3
CVE-2023-4637

The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_prog…

Fix: after 0.9.94
Fix from $1,600 2024-02-05
The Events Calendar MEDIUM 5.3
CVE-2023-6557

The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the ro…

Fix: after 6.2.8.2
Fix from $1,600 2024-02-05
Spectrum Protect Plus HIGH 7.5
CVE-2023-47148

IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper …

Fix: 10.1.15.3+
Fix from $1,950 2024-02-02
Orbit Fox MEDIUM 5.3
CVE-2024-1047

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability c…

Fix: after 2.10.28
Fix from $1,600 2024-02-02
Guardian MEDIUM 5.4
CVE-2023-22836

In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed…

Fix: 2.278.0+
Fix from $1,600 2024-01-29
One Smartedge Agent HIGH 7.8
CVE-2023-1705

Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Fun…

Fix: 1.7.0.230330-554+
Fix from $1,950 2024-01-29
Sites Library HIGH 7.1
CVE-2023-6279

The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as sub…

Fix: 1.4.8+
Fix from $1,950 2024-01-29