Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2024-9202 In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a re… Eclipse Dataspace Components 0.9.1+ Fix from $1,6002024-09-27 MEDIUM 5.3 CVE-2024-9025 The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… Sight 1.1.3+ Fix from $1,6002024-09-26 HIGH 8.8 CVE-2024-47330 Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsys… Slider 1.8.7+ Fix from $1,9502024-09-26 MEDIUM 5.3 CVE-2024-8678 The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the … Revolut Gateway For Woocommerce 4.17.4+ Fix from $1,6002024-09-25 MEDIUM 5.3 CVE-2024-6845 The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users… Chatbot With Chatgpt 2.4.6+ Fix from $1,6002024-09-25 MEDIUM 5.3 CVE-2024-8658 The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooComm… Mycred 2.7.4+ Fix from $1,6002024-09-25 HIGH 7.2 CVE-2024-8349 The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is du… Uncanny Groups For Learndash 6.1.1+ Fix from $1,9502024-09-25 MEDIUM 6.5 CVE-2022-25768 The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. … Mautic 4.4.13 / 5.1.1+ Fix from $1,6002024-09-18 HIGH 8.5 CVE-2024-6406 Missing Authentication for Critical Function, Missing Authorization vulnerability in Yordam Information Technology Mobile Library Application allows … Mitigation only Fix from $1,9502024-09-18 MEDIUM 5.3 CVE-2024-40852 This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to s… Ipados 18.0+ Fix from $1,6002024-09-17 HIGH 7.5 CVE-2024-4660 An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all… GitLab 17.1.7 / 17.2.5+ Fix from $1,9502024-09-12 HIGH 7.5 CVE-2024-3305 Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensiti… Soliclub 4.4.0 / 5.2.1+ Fix from $1,9502024-09-12 MEDIUM 5.3 CVE-2024-7727 The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil… Html5 Video Player 2.5.33+ Fix from $1,6002024-09-11 HIGH 7.8 CVE-2024-40650 In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of p… Android Patch available Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-40652 In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing pe… Android Patch available Fix from $1,9502024-09-11 MEDIUM 5.3 CVE-2024-45591 XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed in… Xwiki 15.10.9 / 16.3.0+ Fix from $1,6002024-09-10 MEDIUM 6.4 CVE-2024-45393 Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can acc… Computer Vision Annotation Tool 2.18.0+ Fix from $1,6002024-09-10 MEDIUM 5.3 CVE-2024-8369 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected eve… Eventprime 4.0.4.4+ Fix from $1,6002024-09-10 MEDIUM 5.4 CVE-2024-45285 The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. By s… Mitigation only Fix from $1,6002024-09-10 MEDIUM 5.4 CVE-2024-44117 The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and… Mitigation only Fix from $1,6002024-09-10 MEDIUM 6.5 CVE-2024-45286 Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting … Mitigation only Fix from $1,6002024-09-10 MEDIUM 5.4 CVE-2024-42371 The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to … Mitigation only Fix from $1,6002024-09-10 HIGH 7.8 CVE-2024-40709 A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level. Mitigation only Fix from $1,9502024-09-07 HIGH 7.8 CVE-2023-39298 A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… Qts Mitigation only Fix from $1,9502024-09-06 HIGH 7.5 CVE-2024-44408 D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the down… Dir 823g Firmware No fix yet Fix from $1,9502024-09-06 HIGH 7.5 CVE-2024-1744 Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive… Accord Ors 7.3.2.1+ Fix from $1,9502024-09-06 HIGH 8.8 CVE-2024-8480 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… Sirv 7.2.8+ Fix from $1,9502024-09-06 MEDIUM 5.3 CVE-2024-7381 The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the a… Geo Controller after 8.6.9 Fix from $1,6002024-09-05 MEDIUM 6.5 CVE-2024-6332 The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to… Amelia after 7.7 Fix from $1,6002024-09-05 MEDIUM 5.4 CVE-2024-5309 The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missi… Form Vibes 1.4.13+ Fix from $1,6002024-09-05