Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.1 CVE-2024-21250 Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). … Process Manufacturing Product Development Mitigation only Fix from $1,9502024-10-15 HIGH 8.1 CVE-2024-21252 Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.… Product Hub after 12.2.13 Fix from $1,9502024-10-15 HIGH 8.8 CVE-2024-21254 Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.… Bi Publisher Mitigation only Fix from $1,9502024-10-15 HIGH 7.5 CVE-2024-21246 Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version that is affe… Service Bus Mitigation only Fix from $1,9502024-10-15 HIGH 7.5 CVE-2024-21234 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Mitigation only Fix from $1,9502024-10-15 HIGH 7.5 CVE-2024-21215 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Fusion Middleware Mitigation only Fix from $1,9502024-10-15 CRITICAL 9.8 CVE-2024-21216 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Mitigation only Fix from $2,3002024-10-15 MEDIUM 6.5 CVE-2024-45732 In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2… Splunk 9.1.2308.208 / 9.1.2312.110+ Fix from $1,6002024-10-14 MEDIUM 5.4 CVE-2024-9860 The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'imp… Mitigation only Fix from $1,6002024-10-12 CRITICAL 9.8 CVE-2024-9707EPSS 9% The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-jso… Hunk Companion 1.8.5+ Fix from $2,3002024-10-11 MEDIUM 5.3 CVE-2024-9586 The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_auth' and 'check… Linkz.ai 1.2.0+ Fix from $1,6002024-10-11 CRITICAL 9.8 CVE-2024-9234EPSS 10% The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads d… Mitigation only Fix from $2,3002024-10-11 MEDIUM 5.4 CVE-2024-48902 In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API Youtrack 2024.3.46677+ Fix from $1,6002024-10-10 MEDIUM 5.4 CVE-2024-9520 The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple … Userplus after 2.0 Fix from $1,6002024-10-10 MEDIUM 5.3 CVE-2024-9065 The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send… Wp Helper Premium after 4.6.1 Fix from $1,6002024-10-10 MEDIUM 5.3 CVE-2024-8513 The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable to unauthorized modification… Qa Analytics after 4.1.0.0 Fix from $1,6002024-10-10 MEDIUM 5.3 CVE-2024-9671 A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invo… 3scale Api Management Platform Mitigation only Fix from $1,6002024-10-09 MEDIUM 5.0 CVE-2024-42934 OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with… Mitigation only Fix from $1,6002024-10-09 HIGH 8.8 CVE-2024-38179 Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability Azure Stack Hci Patch available Fix from $1,9502024-10-08 MEDIUM 6.5 CVE-2024-9161 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a m… Seo 1.0.229+ Fix from $1,6002024-10-05 HIGH 8.1 CVE-2024-47768 Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery … Lif Authentication Server 1.7.3+ Fix from $1,9502024-10-04 HIGH 8.7 CVE-2024-47790 ** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-Time Streaming Protocol (RTSP… Mitigation only Fix from $1,9502024-10-04 MEDIUM 5.4 CVE-2024-20477 A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files… Nexus Dashboard 3.2 / 12.2.2+ Fix from $1,6002024-10-02 MEDIUM 5.4 CVE-2024-20442 A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited A… Nexus Dashboard 3.2+ Fix from $1,6002024-10-02 MEDIUM 5.4 CVE-2024-20438 A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an af… Nexus Dashboard 3.2 / 12.2.2+ Fix from $1,6002024-10-02 MEDIUM 5.3 CVE-2024-8430 The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starte… Mitigation only Fix from $1,6002024-10-01 HIGH 8.1 CVE-2024-8548 The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a mis… Kb Support 1.6.7+ Fix from $1,9502024-10-01 MEDIUM 6.5 CVE-2024-8632 The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a m… Kb Support 1.6.7+ Fix from $1,6002024-10-01 MEDIUM 6.3 CVE-2024-9297 A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Affected by this vulnerability i… Railway Reservation System No fix yet Fix from $1,6002024-09-28 MEDIUM 5.3 CVE-2024-9189 The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… Eu\/uk Vat Manager For Woocommerce 2.12.14+ Fix from $1,6002024-09-28