Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.8 CVE-2024-50428 Missing Authorization vulnerability in mondula2016 Multi Step Form multi-step-form allows Exploiting Incorrectly Configured Access Control Security L… Multi Step Form 1.7.22+ Fix from $2,3002024-10-29 MEDIUM 5.3 CVE-2024-50454 Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.Th… Mitigation only Fix from $1,6002024-10-29 MEDIUM 5.3 CVE-2024-50421 Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting… Mitigation only Fix from $1,6002024-10-29 MEDIUM 5.3 CVE-2024-50422 Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… No fix yet Fix from $1,6002024-10-29 MEDIUM 5.4 CVE-2024-50423 Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access Control Security Levels.This… Mitigation only Fix from $1,6002024-10-29 MEDIUM 6.5 CVE-2024-50424 Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access Control Security Levels.This… Mitigation only Fix from $1,6002024-10-29 HIGH 8.8 CVE-2024-50455 Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.Th… Seopress 8.2+ Fix from $1,9502024-10-29 HIGH 8.8 CVE-2024-50456 Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.Th… Seopress after 8.2 Fix from $1,9502024-10-29 CRITICAL 9.8 CVE-2024-50459 Missing Authorization vulnerability in Hossni Mubarak AidWP wp-stripe-donation allows Exploiting Incorrectly Configured Access Control Security Level… Aidwp 3.2.4+ Fix from $2,3002024-10-29 CRITICAL 9.1 CVE-2024-7475 An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization.… Lunary 1.3.4+ Fix from $2,3002024-10-29 CRITICAL 9.8 CVE-2024-50490 Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects P… Mitigation only Fix from $2,3002024-10-29 CRITICAL 9.8 CVE-2024-50475 Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affects Signup Page: from n/a throu… Mitigation only Fix from $2,3002024-10-29 CRITICAL 9.8 CVE-2024-50476 Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects… Mitigation only Fix from $2,3002024-10-29 MEDIUM 6.5 CVE-2024-10008 The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification du… Masteriyo 1.13.4+ Fix from $1,6002024-10-29 HIGH 7.5 CVE-2024-44208 This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15. An app may be able to bypass certain Privacy pre… macOS 15.0+ Fix from $1,9502024-10-28 HIGH 7.1 CVE-2024-44156 A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Sequoia 15.1, ma… macOS 13.7.1 / 14.7.1+ Fix from $1,9502024-10-28 MEDIUM 5.4 CVE-2024-9629 The Contact Form 7 + Telegram plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability ch… Mitigation only Fix from $1,6002024-10-28 MEDIUM 5.4 CVE-2024-50573 In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services Hub 2024.3.47707+ Fix from $1,6002024-10-28 HIGH 8.8 CVE-2024-10402 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing ca… Forminator Forms 1.36.0+ Fix from $1,9502024-10-26 MEDIUM 5.4 CVE-2024-9584 The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the A… Image Map Pro after 6.0.20 Fix from $1,6002024-10-25 MEDIUM 6.5 CVE-2024-9628 The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on t… Wps Telegram Chat after 4.5.4 Fix from $1,6002024-10-25 MEDIUM 5.3 CVE-2024-9630 The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in version… Wps Telegram Chat after 4.5.4 Fix from $1,6002024-10-25 MEDIUM 5.3 CVE-2024-9686 The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the … Order Notification For Telegram after 1.0.1 Fix from $1,6002024-10-25 HIGH 7.5 CVE-2024-49357EPSS 24% ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpo… Zimaos 1.2.5+ Fix from $1,9502024-10-24 MEDIUM 5.3 CVE-2024-48932 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http://<Ser… Zimaos 1.2.5+ Fix from $1,6002024-10-24 CRITICAL 9.8 CVE-2024-48538 Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzi… Mitigation only Fix from $2,3002024-10-24 MEDIUM 5.3 CVE-2024-49683 Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp allows Accessing Functionali… Mitigation only Fix from $1,6002024-10-24 HIGH 7.7 CVE-2024-49657 Missing Authorization vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Exploiting Incorrectly Configured Access… Mitigation only Fix from $1,9502024-10-23 CRITICAL 9.8 CVE-2024-43924 Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect… Responsive Lightbox 2.4.8+ Fix from $2,3002024-10-23 MEDIUM 5.4 CVE-2024-9583 The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality d… Rss Aggregator 4.23.13+ Fix from $1,6002024-10-23