Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2024-9829
The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_downloa…
Download Plugin
2.2.1+
HIGH 8.8
CVE-2024-38002
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th…
Digital Experience Platform
7.4.3.112 / 2023.q3.9+
MEDIUM 6.3
CVE-2024-10003
The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple…
Rover Idx
3.0.0.2905+
HIGH 7.5
CVE-2024-48645
In Minecraft mod "Command Block IDE" up to and including version 0.4.9, a missing authorization (CWE-862) allows any user to modify "function" files …
Patch available
HIGH 7.5
CVE-2024-49367
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be…
Nginx Ui
after 1.9.9-4
MEDIUM 6.5
CVE-2024-49273
Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects ProfileGrid : from …
Profilegrid
after 5.9.3
MEDIUM 5.4
CVE-2024-49293
Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…
Wp Vr
after 8.5.4
HIGH 8.8
CVE-2024-49325
Missing Authorization vulnerability in wpdiscover Photo Gallery Builder photo-gallery-builder allows Accessing Functionality Not Properly Constrained…
Photo Gallery Builder
after 3.0
MEDIUM 6.3
CVE-2024-10078
The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on…
Wp Easy Post Types
after 1.4.4
HIGH 7.1
CVE-2024-20463
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remot…
Ata 191 Firmware
11.2.5 / 12.0.2+
MEDIUM 6.3
CVE-2024-45461
The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. …
Cloudstack
4.18.2.4 / 4.19.1.2+
CRITICAL 9.8
CVE-2020-36840
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_…
Timetable And Event Schedule
2.3.9+
MEDIUM 6.5
CVE-2023-7294
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check …
Paytium
4.4.0+
HIGH 8.1
CVE-2023-7291
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che…
Paytium
4.4.0+
MEDIUM 5.4
CVE-2023-7287
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capabilit…
Paytium
4.4.0+
HIGH 7.5
CVE-2022-4972
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related …
Download Monitor
after 4.7.51
MEDIUM 6.3
CVE-2022-4974
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosu…
Mitigation only
HIGH 8.8
CVE-2021-4447
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of…
Essential Addons For Elementor
4.6.5+
CRITICAL 9.8
CVE-2021-4448
The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient c…
Kaswara
after 3.0.1
HIGH 7.3
CVE-2021-4444
The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing autho…
Mitigation only
MEDIUM 6.3
CVE-2020-36834
The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and includ…
Mitigation only
MEDIUM 6.5
CVE-2020-36835
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to…
Migration\, Backup\, Staging
0.9.36+
CRITICAL 9.9
CVE-2020-36837
The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_action…
Mitigation only
CRITICAL 9.8
CVE-2019-25217
The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in vers…
Speed Optimizer
5.0.12+
MEDIUM 6.5
CVE-2020-36831
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple …
Social Networks Auto Poster
4.3.18+
MEDIUM 6.3
CVE-2020-36833
The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in vers…
Mitigation only
MEDIUM 6.1
CVE-2019-25214
The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to,…
Shopwp
after 2.0.4
HIGH 7.3
CVE-2019-25215
The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin i…
Ari Adminer
after 1.1.14
CRITICAL 9.8
CVE-2018-25105
The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions …
File Manager
after 3.0
HIGH 8.6
CVE-2024-38190
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
Power Platform
Patch available