Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2024-50417 Missing Authorization vulnerability in boldthemes Bold Page Builder bold-page-builder allows Exploiting Incorrectly Configured Access Control Securit… Bold Page Builder 5.1.4+ Fix from $1,9502024-11-19 MEDIUM 5.4 CVE-2024-49689 Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light hd-quiz-save-results-light allows Exploiting Incorrectly Configur… Mitigation only Fix from $1,6002024-11-19 HIGH 8.8 CVE-2024-11194 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can … Mitigation only Fix from $1,9502024-11-19 CRITICAL 9.1 CVE-2024-11069 The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'WordPress_GDPR_Data_Dele… Wordpress Gdpr 2.0.3+ Fix from $2,3002024-11-19 MEDIUM 5.3 CVE-2024-10486 The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to p… Mitigation only Fix from $1,6002024-11-18 MEDIUM 6.4 CVE-2024-10390 The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePre… Mitigation only Fix from $1,6002024-11-18 MEDIUM 5.3 CVE-2024-52921 In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block. Bitcoin Core 25.0+ Fix from $1,6002024-11-18 CRITICAL 10.0 CVE-2024-52416 Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool:… Mitigation only Fix from $2,3002024-11-16 HIGH 8.8 CVE-2024-10728EPSS 36% The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation du… Postx 4.1.17+ Fix from $1,9502024-11-16 MEDIUM 5.4 CVE-2024-11085 The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on several AJAX actions i… Mitigation only Fix from $1,6002024-11-16 MEDIUM 5.3 CVE-2024-10861 The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a… Mitigation only Fix from $1,6002024-11-16 HIGH 7.8 CVE-2017-13314 In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul… Android Patch available Fix from $1,9502024-11-15 CRITICAL 9.8 CVE-2024-52382 Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue affects Matix Popup Builder: … Mitigation only Fix from $2,3002024-11-14 HIGH 7.5 CVE-2024-52383 Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One ai-auto-tool allows Exploit… Mitigation only Fix from $1,9502024-11-14 MEDIUM 5.4 CVE-2022-31666 Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of ot… Harbor 2.4.3 / 2.5.2+ Fix from $1,6002024-11-14 HIGH 8.8 CVE-2024-52554 Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not … Shared Library Version Override after 17.v786074c9fce7 Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43087 In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the access… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43088 In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due … Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43089 In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc… Android Patch available Fix from $1,9502024-11-13 MEDIUM 5.0 CVE-2024-43090 In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure w… Android No fix yet Fix from $1,6002024-11-13 HIGH 7.8 CVE-2024-34719 In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no a… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-40661 In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission chec… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-40671 In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This … Android Mitigation only Fix from $1,9502024-11-13 CRITICAL 9.8 CVE-2024-10575 CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connec… Ecostruxure It Gateway Patch available Fix from $2,3002024-11-13 HIGH 8.8 CVE-2024-10800 The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields(… User Extra Fields 16.7+ Fix from $1,9502024-11-13 MEDIUM 5.3 CVE-2024-10802 The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_… Hash Elements 1.4.8+ Fix from $1,6002024-11-13 MEDIUM 5.3 CVE-2024-10529 The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the … Kognetiks Chatbot 2.1.8+ Fix from $1,6002024-11-13 MEDIUM 5.3 CVE-2024-9578 The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filte… Hide Links after 1.4.2 Fix from $1,6002024-11-13 HIGH 8.8 CVE-2024-10629 The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file type validation in the gpxv_f… Mitigation only Fix from $1,9502024-11-13 MEDIUM 6.5 CVE-2024-10717 The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a miss… Styler For Ninja Forms after 3.3.4 Fix from $1,6002024-11-13