Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2024-9829 The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_downloa… Download Plugin 2.2.1+ Fix from $1,6002024-10-23 HIGH 8.8 CVE-2024-38002 The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th… Digital Experience Platform 7.4.3.112 / 2023.q3.9+ Fix from $1,9502024-10-22 MEDIUM 6.3 CVE-2024-10003 The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple… Rover Idx 3.0.0.2905+ Fix from $1,6002024-10-22 HIGH 7.5 CVE-2024-48645 In Minecraft mod "Command Block IDE" up to and including version 0.4.9, a missing authorization (CWE-862) allows any user to modify "function" files … Patch available Fix from $1,9502024-10-21 HIGH 7.5 CVE-2024-49367 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be… Nginx Ui after 1.9.9-4 Fix from $1,9502024-10-21 MEDIUM 6.5 CVE-2024-49273 Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects ProfileGrid : from … Profilegrid after 5.9.3 Fix from $1,6002024-10-21 MEDIUM 5.4 CVE-2024-49293 Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… Wp Vr after 8.5.4 Fix from $1,6002024-10-21 HIGH 8.8 CVE-2024-49325 Missing Authorization vulnerability in wpdiscover Photo Gallery Builder photo-gallery-builder allows Accessing Functionality Not Properly Constrained… Photo Gallery Builder after 3.0 Fix from $1,9502024-10-20 MEDIUM 6.3 CVE-2024-10078 The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on… Wp Easy Post Types after 1.4.4 Fix from $1,6002024-10-18 HIGH 7.1 CVE-2024-20463 A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remot… Ata 191 Firmware 11.2.5 / 12.0.2+ Fix from $1,9502024-10-16 MEDIUM 6.3 CVE-2024-45461 The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. … Cloudstack 4.18.2.4 / 4.19.1.2+ Fix from $1,6002024-10-16 CRITICAL 9.8 CVE-2020-36840 The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_… Timetable And Event Schedule 2.3.9+ Fix from $2,3002024-10-16 MEDIUM 6.5 CVE-2023-7294 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check … Paytium 4.4.0+ Fix from $1,6002024-10-16 HIGH 8.1 CVE-2023-7291 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… Paytium 4.4.0+ Fix from $1,9502024-10-16 MEDIUM 5.4 CVE-2023-7287 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capabilit… Paytium 4.4.0+ Fix from $1,6002024-10-16 HIGH 7.5 CVE-2022-4972 The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related … Download Monitor after 4.7.51 Fix from $1,9502024-10-16 MEDIUM 6.3 CVE-2022-4974 The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosu… Mitigation only Fix from $1,6002024-10-16 HIGH 8.8 CVE-2021-4447 The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of… Essential Addons For Elementor 4.6.5+ Fix from $1,9502024-10-16 CRITICAL 9.8 CVE-2021-4448 The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient c… Kaswara after 3.0.1 Fix from $2,3002024-10-16 HIGH 7.3 CVE-2021-4444 The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing autho… Mitigation only Fix from $1,9502024-10-16 MEDIUM 6.3 CVE-2020-36834 The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and includ… Mitigation only Fix from $1,6002024-10-16 MEDIUM 6.5 CVE-2020-36835 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to… Migration\, Backup\, Staging 0.9.36+ Fix from $1,6002024-10-16 CRITICAL 9.9 CVE-2020-36837 The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_action… Mitigation only Fix from $2,3002024-10-16 CRITICAL 9.8 CVE-2019-25217 The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in vers… Speed Optimizer 5.0.12+ Fix from $2,3002024-10-16 MEDIUM 6.5 CVE-2020-36831 The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple … Social Networks Auto Poster 4.3.18+ Fix from $1,6002024-10-16 MEDIUM 6.3 CVE-2020-36833 The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in vers… Mitigation only Fix from $1,6002024-10-16 MEDIUM 6.1 CVE-2019-25214 The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to,… Shopwp after 2.0.4 Fix from $1,6002024-10-16 HIGH 7.3 CVE-2019-25215 The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin i… Ari Adminer after 1.1.14 Fix from $1,9502024-10-16 CRITICAL 9.8 CVE-2018-25105 The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions … File Manager after 3.0 Fix from $2,3002024-10-16 HIGH 8.6 CVE-2024-38190 Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. Power Platform Patch available Fix from $1,9502024-10-15