Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Mercari MEDIUM 6.1
CVE-2024-23388

Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a…

Fix: 5.78.0+
Fix from $1,600 2024-01-26
GitLab MEDIUM 5.3
CVE-2023-5612

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read …

Fix: 16.6.6 / 16.7.4+
Fix from $1,600 2024-01-26
Category Discount Woocommerce MEDIUM 5.3
CVE-2024-0617

The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp…

Fix: 4.13+
Fix from $1,600 2024-01-25
Airflow MEDIUM 6.5
CVE-2023-50944

Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't …

Fix: 2.8.1+
Fix from $1,600 2024-01-24
Pandasai CRITICAL 9.8
CVE-2024-23752

GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python …

Fix: after 1.5.17
Fix from $2,300 2024-01-22
Colormag MEDIUM 6.5
CVE-2024-0679

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in a…

Fix: after 3.1.2
Fix from $1,600 2024-01-20
Wip Custom Login HIGH 8.8
CVE-2022-42884

Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a through 1.2.7.

Fix: after 1.2.7
Fix from $1,950 2024-01-17
Wp Job Portal CRITICAL 9.8
CVE-2022-41786

Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: fr…

Fix: after 2.0.1
Fix from $2,300 2024-01-17
Wp Time Slots Booking Form HIGH 8.8
CVE-2022-41790

Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.

Fix: after 1.1.76
Fix from $1,950 2024-01-17
Url Shortener HIGH 8.8
CVE-2023-23896

Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0…

Fix: after 1.0.17
Fix from $1,950 2024-01-17
Image Zoom MEDIUM 6.5
CVE-2022-41619

Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8.

Fix: after 1.8.8
Fix from $1,600 2024-01-17
Traffic Manager MEDIUM 6.5
CVE-2022-41695

Missing Authorization vulnerability in SedLex Traffic Manager.This issue affects Traffic Manager: from n/a through 1.4.5.

Fix: after 1.4.5
Fix from $1,600 2024-01-17
Sales Report Email For Woocommerce MEDIUM 6.5
CVE-2022-38141

Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a throu…

Fix: after 2.8
Fix from $1,600 2024-01-17
Advanced Dynamic Pricing For Woocommerce HIGH 8.8
CVE-2022-40203

Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce…

Fix: 4.1.6+
Fix from $1,950 2024-01-17
Hreflang Tags Lite CRITICAL 9.8
CVE-2022-36418

Missing Authorization vulnerability in Vagary Digital HREFLANG Tags Lite.This issue affects HREFLANG Tags Lite: from n/a through 2.0.0.

Fix: after 2.0.0
Fix from $2,300 2024-01-17
Advanced Loyalty Program MEDIUM 5.3
CVE-2023-48926

An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily chang…

Fix: 2.3.4+
Fix from $1,600 2024-01-16
Eventon MEDIUM 5.3
CVE-2024-0235EPSS 38%

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticate…

Fix: 2.2.7 / 4.5.5+
Fix from $1,600 2024-01-16
Eventon MEDIUM 5.3
CVE-2024-0236

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticate…

Fix: 2.2.7 / 4.5.5+
Fix from $1,600 2024-01-16
Eventon MEDIUM 5.3
CVE-2024-0237

The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenti…

Fix: 2.2.7 / 4.5.5+
Fix from $1,600 2024-01-16
Eventon MEDIUM 6.1
CVE-2024-0238

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not en…

Fix: 2.2.7 / 4.5.5+
Fix from $1,600 2024-01-16
N350rt Firmware CRITICAL 9.1
CVE-2024-0570

A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $2,300 2024-01-16
T8 Firmware CRITICAL 9.1
CVE-2024-0569

A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /…

No fix yet
Fix from $2,300 2024-01-16
Aria Automation HIGH 8.3
CVE-2023-34063

Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauth…

Patch available
Fix from $1,950 2024-01-16
Export Posts With Images HIGH 8.1
CVE-2023-5905

The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog …

Fix: after 20220825
Fix from $1,950 2024-01-15
Eazydocs HIGH 7.5
CVE-2023-6029

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are docu…

Fix: 2.3.6+
Fix from $1,950 2024-01-15
Estatik MEDIUM 6.5
CVE-2023-6048

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting an…

Fix: 4.1.1+
Fix from $1,600 2024-01-15
GitLab MEDIUM 5.3
CVE-2023-6955

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7…

Fix: 16.5.6 / 16.6.4+
Fix from $1,600 2024-01-12
Tcexam MEDIUM 6.5
CVE-2023-6554

When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to d…

Fix: 15.1.0+
Fix from $1,600 2024-01-11
Paid Memberships Pro MEDIUM 5.3
CVE-2023-6855

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modificati…

Fix: after 2.12.5
Fix from $1,600 2024-01-11
Post Smtp CRITICAL 9.8
CVE-2023-6875EPSS 90%

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized …

Fix: after 2.8.7
Fix from $2,300 2024-01-11