Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Hostinger MEDIUM 6.5
CVE-2023-6751

The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_web…

Fix: after 1.9.7
Fix from $1,600 2024-01-11
Complete Analytics Optimization Suite MEDIUM 5.3
CVE-2023-6637

The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on…

Fix: 4.7.15+
Fix from $1,600 2024-01-11
Gg Woo Feed MEDIUM 5.3
CVE-2023-6638

The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'u…

Fix: after 1.2.4
Fix from $1,600 2024-01-11
Export Wp Page To Static Html\/css MEDIUM 5.4
CVE-2023-6369

The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing cap…

Fix: after 2.1.9
Fix from $1,600 2024-01-11
Manage Notification E Mails MEDIUM 5.3
CVE-2023-6496

The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_…

Fix: 1.8.6+
Fix from $1,600 2024-01-11
Eventon MEDIUM 6.5
CVE-2023-6158

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to…

Fix: after 4.5.4
Fix from $1,600 2024-01-10
Nexo Os CRITICAL 9.8
CVE-2023-48245

The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a cra…

Fix: after 1500-sp2
Fix from $2,300 2024-01-10
Nexo Os HIGH 7.5
CVE-2023-48247

The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application OS user (“root”) via a craft…

Fix: after 1500-sp2
Fix from $1,950 2024-01-10
Wholesale Suite HIGH 8.8
CVE-2022-34344

Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Ro…

Fix: after 2.1.5
Fix from $1,950 2024-01-08
Profilegrid HIGH 8.8
CVE-2022-36352

Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – …

Fix: after 5.0.3
Fix from $1,950 2024-01-08
Debug Log Manager HIGH 7.5
CVE-2023-6383

The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug…

Fix: 2.3.0+
Fix from $1,950 2024-01-08
Rss Aggregator By Feedzy MEDIUM 5.4
CVE-2023-6798

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized s…

Fix: 4.3.3+
Fix from $1,600 2024-01-06
Wp Members MEDIUM 6.5
CVE-2023-6733

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via…

Fix: after 3.4.8
Fix from $1,600 2024-01-04
Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels MEDIUM 6.5
CVE-2023-7068

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due…

Fix: 4.3.1+
Fix from $1,600 2024-01-03
Ric Plt E2mgr HIGH 7.7
CVE-2023-42358

An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial of service …

No fix yet
Fix from $1,950 2024-01-03
Omgf MEDIUM 5.4
CVE-2023-6600

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-…

Fix: 5.7.10+
Fix from $1,600 2024-01-03
Android MEDIUM 5.5
CVE-2023-4164

There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no …

Mitigation only
Fix from $1,600 2024-01-02
Springblade CRITICAL 9.8
CVE-2023-47458

An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.

Fix: after 3.7.0
Fix from $2,300 2024-01-02
Affiliate Toolkit CRITICAL 9.8
CVE-2023-5877

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_…

Fix: 3.4.3+
Fix from $2,300 2024-01-01
Trio 8800 Firmware HIGH 7.6
CVE-2023-4468

A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the compo…

Mitigation only
Fix from $1,950 2023-12-29
Advanced Custom Fields\ HIGH 8.8
CVE-2023-22676

Missing Authorization vulnerability in Anders Thorborg.This issue affects Anders Thorborg: from n/a through 1.4.12.

Fix: after 1.4.12
Fix from $1,950 2023-12-29
Balance Two Firmware HIGH 8.8
CVE-2023-49230

An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals'…

Fix: 8.4.0+
Fix from $1,950 2023-12-28
Simple Dialer MEDIUM 5.3
CVE-2023-49003

An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interaction with com.simplemobiletoo…

No fix yet
Fix from $1,600 2023-12-27
Hertzbeat HIGH 7.5
CVE-2023-51650

Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized acc…

Fix: 1.4.1+
Fix from $1,950 2023-12-22
Dashicons \+ Custom Post Types HIGH 8.8
CVE-2023-22674

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + C…

Fix: after 1.0.2
Fix from $1,950 2023-12-21
Gamipress MEDIUM 6.5
CVE-2023-25715

Missing Authorization vulnerability in GamiPress GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress.T…

Fix: after 2.5.6
Fix from $1,600 2023-12-19
Wp Extra HIGH 8.8
CVE-2023-46212

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionality Not Properly Constrained by…

Fix: after 6.2
Fix from $1,950 2023-12-19
Delete Duplicate Posts CRITICAL 9.8
CVE-2023-47754

Missing Authorization vulnerability in Clever plugins Delete Duplicate Posts allows Accessing Functionality Not Properly Constrained by ACLs.This iss…

Fix: after 4.8.9
Fix from $2,300 2023-12-19
Participants Database HIGH 8.8
CVE-2023-48751

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functi…

Fix: after 2.5.5
Fix from $1,950 2023-12-19
Smartcrawl HIGH 7.5
CVE-2023-5949

The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content.

Fix: 3.8.3+
Fix from $1,950 2023-12-18