Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Wcfm Membership CRITICAL 9.8
CVE-2022-4939

THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability c…

Fix: 2.10.1+
Fix from $2,300 2023-04-05
Wcfm Membership MEDIUM 6.5
CVE-2022-4940

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due t…

Fix: 2.10.11+
Fix from $1,600 2023-04-05
Wcfm Marketplace HIGH 8.8
CVE-2022-4935

The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due …

Fix: 3.4.12+
Fix from $1,950 2023-04-05
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible HIGH 8.8
CVE-2022-4937

The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 …

Fix: 6.6.1+
Fix from $1,950 2023-04-05
Yourchannel MEDIUM 6.5
CVE-2023-1865

The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when resetting plugin settings via…

Fix: after 1.2.3
Fix from $1,600 2023-04-05
Yourchannel MEDIUM 5.3
CVE-2023-1868

The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via …

Fix: after 1.2.3
Fix from $1,600 2023-04-05
James HIGH 7.8
CVE-2023-26269

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation b…

Fix: 3.7.4+
Fix from $1,950 2023-04-03
Octoperf Load Testing MEDIUM 6.5
CVE-2023-28672

Jenkins OctoPerf Load Testing Plugin Plugin 4.5.1 and earlier does not perform a permission check in a connection test HTTP endpoint, allowing attack…

Fix: after 4.5.1
Fix from $1,600 2023-04-02
Mattermost Server MEDIUM 5.4
CVE-2023-1774

When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an at…

Fix: 7.1.6+
Fix from $1,600 2023-03-31
Muyucms HIGH 8.1
CVE-2023-27701

MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html.

No fix yet
Fix from $1,950 2023-03-28
Emui HIGH 7.5
CVE-2022-48350

The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,950 2023-03-27
Wp Shamsi MEDIUM 6.5
CVE-2023-0335

The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delet…

Fix: after 4.3.3
Fix from $1,600 2023-03-27
Ooohboi Steroids For Elementor MEDIUM 6.5
CVE-2023-0336

The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low…

Fix: 2.1.5+
Fix from $1,600 2023-03-27
Android HIGH 7.8
CVE-2023-21015

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This c…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-21021

In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin user network settings due to …

Patch available
Fix from $1,950 2023-03-24
Android MEDIUM 5.5
CVE-2023-21029

In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with Use…

Patch available
Fix from $1,600 2023-03-24
Android HIGH 7.8
CVE-2023-21001

In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings of other users due to a miss…

Patch available
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-21002

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This c…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-21003

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This c…

Patch available
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-21004

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This c…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-21005

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This c…

Patch available
Fix from $1,950 2023-03-24
Android MEDIUM 6.8
CVE-2023-20926

In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due to a missing permission check.…

Patch available
Fix from $1,600 2023-03-24
Android HIGH 7.8
CVE-2023-20955

In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and uninstall applications for all use…

Patch available
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-20959

In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local es…

Mitigation only
Fix from $1,950 2023-03-24
Wi Sun Software Development Kit MEDIUM 5.3
CVE-2023-1261

Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network.

Fix: after 1.5.0
Fix from $1,600 2023-03-21
Wireless Smart Ubiquitous Network Linux Border Router Firmware MEDIUM 5.3
CVE-2023-1262

Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through ne…

Fix: after 1.5.2
Fix from $1,600 2023-03-21
Bofei Dbd\+ HIGH 8.1
CVE-2022-45636

An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitra…

No fix yet
Fix from $1,950 2023-03-21
Shortcodes Ultimate MEDIUM 6.5
CVE-2023-0890

The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes a…

Fix: 5.12.8+
Fix from $1,600 2023-03-20
Shortcodes Ultimate MEDIUM 6.5
CVE-2023-0911

The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user sho…

Fix: 5.12.8+
Fix from $1,600 2023-03-20
Nomad MEDIUM 5.3
CVE-2023-1296

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and …

Fix: 1.4.6+
Fix from $1,600 2023-03-14