Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2024-54153 In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter Youtrack 2024.3.51866+ Fix from $1,6002024-12-04 HIGH 7.5 CVE-2024-10567 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard'… Mitigation only Fix from $1,9502024-12-04 HIGH 8.1 CVE-2024-42453 A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts… Veeam Backup \& Replication 12.3.0.310+ Fix from $1,9502024-12-04 HIGH 8.8 CVE-2024-53938 An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by defau… Mitigation only Fix from $1,9502024-12-02 MEDIUM 6.5 CVE-2024-49581 Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn'… Mitigation only Fix from $1,6002024-12-02 MEDIUM 5.3 CVE-2024-53708 Missing Authorization vulnerability in kekotron AI Quiz ai-quiz allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AI… Mitigation only Fix from $1,6002024-12-02 HIGH 7.5 CVE-2024-53605 Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers t… Mitigation only Fix from $1,9502024-12-02 HIGH 7.8 CVE-2017-13316 In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local es… Android Patch available Fix from $1,9502024-11-27 MEDIUM 5.3 CVE-2024-10580 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing ca… Mitigation only Fix from $1,6002024-11-27 HIGH 8.8 CVE-2024-8114 An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue a… GitLab 17.4.5 / 17.5.3+ Fix from $1,9502024-11-26 HIGH 7.5 CVE-2024-10542EPSS 15% The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an auth… Anti Spam 6.44+ Fix from $1,9502024-11-26 MEDIUM 6.5 CVE-2024-49596 Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access c… Wyse Management Suite after 4.4 Fix from $1,6002024-11-26 MEDIUM 5.3 CVE-2024-53258 Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download a… Autolab after 3.0.2 Fix from $1,6002024-11-25 HIGH 7.8 CVE-2024-8272 The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-pro… Mitigation only Fix from $1,9502024-11-25 HIGH 8.8 CVE-2024-9941 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gm… Wordpress Gym Management System 67.2.0+ Fix from $1,9502024-11-23 HIGH 7.5 CVE-2024-10813 The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all … Woo Product Table 3.5.2+ Fix from $1,9502024-11-23 HIGH 7.6 CVE-2024-0122 NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker may cause an unauthorized action. A success… No fix yet Fix from $1,9502024-11-23 CRITICAL 9.8 CVE-2024-0138 NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability mig… Mitigation only Fix from $2,3002024-11-23 HIGH 8.1 CVE-2024-11104 The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for W… Sky Addons For Elementor 2.6.3+ Fix from $1,9502024-11-22 HIGH 8.1 CVE-2024-11601 The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery… Sky Addons For Elementor 2.6.2+ Fix from $1,9502024-11-22 MEDIUM 5.3 CVE-2024-11334 The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportar_registros() … My Contador Lesr 2.1+ Fix from $1,6002024-11-21 MEDIUM 5.3 CVE-2024-10393 The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing che… Tutor Lms after 2.7.6 Fix from $1,6002024-11-21 HIGH 7.8 CVE-2018-9477 In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead … Android Patch available Fix from $1,9502024-11-20 HIGH 7.8 CVE-2018-9469 In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead … Android Patch available Fix from $1,9502024-11-20 MEDIUM 5.3 CVE-2024-10520 The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' metho… Wp Project Manager 2.6.15+ Fix from $1,6002024-11-20 MEDIUM 6.5 CVE-2024-45689 A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they… Moodle 4.1.13 / 4.2.10+ Fix from $1,6002024-11-20 MEDIUM 5.4 CVE-2024-10665 The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data due to a missing capability ch… Mitigation only Fix from $1,6002024-11-20 HIGH 8.1 CVE-2024-10900 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… Profilegrid 5.9.3.7+ Fix from $1,9502024-11-20 MEDIUM 5.3 CVE-2024-52395 Missing Authorization vulnerability in QuantumCloud Floating Buttons for WooCommerce shop-assistant-for-woocommerce-jarvis allows Exploiting Incorrec… Mitigation only Fix from $1,6002024-11-19 MEDIUM 5.4 CVE-2024-51817 Missing Authorization vulnerability in CodeZel Combo WP Rewrite Slugs combo-wp-rewrite-slugs allows Exploiting Incorrectly Configured Access Control … Mitigation only Fix from $1,6002024-11-19