Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.1 CVE-2022-46838 Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Co… Js Help Desk 2.7.2+ Fix from $2,3002024-12-13 MEDIUM 5.4 CVE-2022-46840 Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Co… Js Help Desk 2.7.2+ Fix from $1,6002024-12-13 MEDIUM 5.3 CVE-2022-46846 Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Trending/Popular Post Slider and Widget allows Exploiting Incorrectly Confi… Mitigation only Fix from $1,6002024-12-13 MEDIUM 5.4 CVE-2022-45826 Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This i… Sunshine Photo Cart 2.9.14+ Fix from $1,6002024-12-13 MEDIUM 6.5 CVE-2022-45840 Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.Th… Mitigation only Fix from $1,6002024-12-13 MEDIUM 5.4 CVE-2022-45841 Missing Authorization vulnerability in RoboSoft Robo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec… Mitigation only Fix from $1,6002024-12-13 MEDIUM 6.5 CVE-2022-46795 Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access… Print Invoice \& Delivery Notes For Woocommerce 4.7.3+ Fix from $1,6002024-12-13 MEDIUM 6.5 CVE-2022-46796 Missing Authorization vulnerability in VillaTheme CURCY allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CU… Mitigation only Fix from $1,6002024-12-13 MEDIUM 5.3 CVE-2022-44578 Missing Authorization vulnerability in Pierre JEHAN Owl Carousel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a… No fix yet Fix from $1,6002024-12-13 CRITICAL 9.8 CVE-2022-45806 Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security… Formidable Forms 5.5.5+ Fix from $2,3002024-12-13 HIGH 8.1 CVE-2024-10783 The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due … Mitigation only Fix from $1,9502024-12-13 HIGH 8.8 CVE-2024-55879 XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arb… Xwiki 15.10.9 / 16.3.0+ Fix from $1,9502024-12-12 MEDIUM 5.4 CVE-2024-55876 XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on … Xwiki 15.10.9 / 16.3.0+ Fix from $1,6002024-12-12 MEDIUM 5.3 CVE-2024-12265 The Web3 Crypto Payments by DePay for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… Mitigation only Fix from $1,6002024-12-12 HIGH 7.5 CVE-2024-12172 The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorize… Mitigation only Fix from $1,9502024-12-12 HIGH 8.8 CVE-2024-11443 The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capabi… Mitigation only Fix from $1,9502024-12-12 MEDIUM 5.3 CVE-2024-54466 An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13… macOS 13.7.2 / 14.7.2+ Fix from $1,6002024-12-12 HIGH 7.1 CVE-2024-11840 The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a… Mitigation only Fix from $1,9502024-12-11 MEDIUM 5.3 CVE-2024-11401 Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorizatio… Mitigation only Fix from $1,6002024-12-11 CRITICAL 9.8 CVE-2024-45493 An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is … Mitigation only Fix from $2,3002024-12-10 MEDIUM 6.5 CVE-2024-11205 The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' … Wpforms 1.9.2.2+ Fix from $1,6002024-12-10 HIGH 8.8 CVE-2024-50628 An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local area network to achieve unautho… Connectport Lts Firmware 1.4.12+ Fix from $1,9502024-12-09 HIGH 8.8 CVE-2024-45760 Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user co… Openmanage Server Administrator 11.1.0.0+ Fix from $1,9502024-12-09 MEDIUM 6.5 CVE-2024-54218 Missing Authorization vulnerability in thehp AIO Contact aio-contact.This issue affects AIO Contact: from n/a through <= 2.8.1. Mitigation only Fix from $1,6002024-12-09 MEDIUM 5.3 CVE-2024-52391 Missing Authorization vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3. Mitigation only Fix from $1,6002024-12-09 CRITICAL 9.8 CVE-2024-52480 Missing Authorization vulnerability in Astoundify Jobify jobify.This issue affects Jobify: from n/a through < 4.3.0. Jobify 4.2.4+ Fix from $2,3002024-12-09 MEDIUM 5.3 CVE-2023-41953 Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1. Profilepress 4.13.2+ Fix from $1,6002024-12-09 MEDIUM 6.5 CVE-2024-54251 Missing Authorization vulnerability in prodigycommerce Prodigy Commerce prodigy-commerce allows Exploiting Incorrectly Configured Access Control Secu… Mitigation only Fix from $1,6002024-12-09 MEDIUM 6.3 CVE-2024-54254 Missing Authorization vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter.This issue affects Message Filter for Contact… Mitigation only Fix from $1,6002024-12-09 HIGH 8.8 CVE-2024-53816 Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons.This issue affects Tutor LMS Elementor Addons: f… Tutor Lms Elementor Addons 2.1.6+ Fix from $1,9502024-12-09