Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.8 CVE-2024-11281 The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to … Mitigation only Fix from $2,3002024-12-25 MEDIUM 5.3 CVE-2024-12413 The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capab… No fix yet Fix from $1,6002024-12-25 HIGH 8.8 CVE-2024-12881 The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary file uploads due to a missing… Mitigation only Fix from $1,9502024-12-24 HIGH 8.8 CVE-2024-12594 The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Temporary admin login access , Renam… Mitigation only Fix from $1,9502024-12-24 MEDIUM 5.4 CVE-2024-12617 The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions … Mitigation only Fix from $1,6002024-12-24 MEDIUM 6.5 CVE-2024-12266 The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec… Mitigation only Fix from $1,6002024-12-24 MEDIUM 6.5 CVE-2024-12558 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit… Mitigation only Fix from $1,6002024-12-21 MEDIUM 5.3 CVE-2024-56349 In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs Teamcity 2024.12+ Fix from $1,6002024-12-20 HIGH 8.8 CVE-2024-56048 Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec… Wordpress Learning Management System 1.9.9.1+ Fix from $1,9502024-12-18 HIGH 7.1 CVE-2024-54381 Missing Authorization vulnerability in Dotstore Advance Menu Manager advance-menu-manager.This issue affects Advance Menu Manager: from n/a through <… No fix yet Fix from $1,9502024-12-18 MEDIUM 6.5 CVE-2024-55997 Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-location-date-time-free-version all… Mitigation only Fix from $1,6002024-12-18 HIGH 7.5 CVE-2024-56008 Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality Not Properly Constrained by … Mitigation only Fix from $1,9502024-12-18 MEDIUM 6.5 CVE-2024-52485 Missing Authorization vulnerability in Yudiz Solutions Ltd. WP Menu Image wp-menu-image allows Exploiting Incorrectly Configured Access Control Secur… Mitigation only Fix from $1,6002024-12-18 MEDIUM 6.5 CVE-2024-11926 The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '_… Mitigation only Fix from $1,6002024-12-18 HIGH 8.8 CVE-2024-12259 The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and inc… Mitigation only Fix from $1,9502024-12-18 MEDIUM 5.3 CVE-2024-55999 Missing Authorization vulnerability in Marco Giannini XML Multilanguage Sitemap Generator xml-multilanguage-sitemap-generator.This issue affects XML … Mitigation only Fix from $1,6002024-12-16 MEDIUM 6.5 CVE-2024-56001 Missing Authorization vulnerability in ksher thailand Ksher ksher-payment allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… Mitigation only Fix from $1,6002024-12-16 MEDIUM 5.4 CVE-2024-56004 Missing Authorization vulnerability in awfowler Easy Site Importer easy-site-importer allows Exploiting Incorrectly Configured Access Control Securit… Mitigation only Fix from $1,6002024-12-16 MEDIUM 5.3 CVE-2024-56009 Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality Not Properly Constrained by … Mitigation only Fix from $1,6002024-12-16 MEDIUM 5.4 CVE-2024-55992 Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers woocommerce-basic-ordernumbers allows Exploiting Incorrectly Configu… Mitigation only Fix from $1,6002024-12-16 MEDIUM 5.3 CVE-2024-55993 Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Securi… Mitigation only Fix from $1,6002024-12-16 MEDIUM 6.1 CVE-2024-55996 Missing Authorization vulnerability in dreamfox Dreamfox Media Payment gateway per Product for Woocommerce woocommerce-product-payments allows Exploi… Mitigation only Fix from $1,6002024-12-16 MEDIUM 5.4 CVE-2024-55998 Missing Authorization vulnerability in Eric Sloan Popup Surveys & Polls for WordPress (Mare.io) popup-surveys allows Exploiting Incorrectly Configure… Mitigation only Fix from $1,6002024-12-16 MEDIUM 5.3 CVE-2024-54417 Missing Authorization vulnerability in pixelgrade PixProof pixproof allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect… Mitigation only Fix from $1,6002024-12-16 HIGH 8.8 CVE-2024-54378 Missing Authorization vulnerability in Quietly Quietly Insights quietly-insights allows Privilege Escalation.This issue affects Quietly Insights: fro… Mitigation only Fix from $1,9502024-12-16 HIGH 8.8 CVE-2024-54379 Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects Minterpress: from n/a throug… Mitigation only Fix from $1,9502024-12-16 CRITICAL 9.1 CVE-2024-54369 Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.Th… Mitigation only Fix from $2,3002024-12-16 MEDIUM 6.5 CVE-2024-54354 Missing Authorization vulnerability in beat.k Termin-Kalender termin-kalender allows Stored XSS.This issue affects Termin-Kalender: from n/a through … Mitigation only Fix from $1,6002024-12-16 HIGH 8.2 CVE-2024-54359 Missing Authorization vulnerability in Saul Morales Pacheco Banner System banner-system allows Exploiting Incorrectly Configured Access Control Secur… Mitigation only Fix from $1,9502024-12-16 MEDIUM 5.3 CVE-2024-11712 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data … Wp Job Portal 2.2.3+ Fix from $1,6002024-12-14