Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.1 CVE-2024-45050 Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where Ringer… Patch available Fix from $1,9502024-09-04 CRITICAL 9.8 CVE-2024-8289 The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escalation/de-escalation… Multivendorx 4.2.1+ Fix from $2,3002024-09-04 HIGH 8.8 CVE-2024-8102 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… Wp Extended 3.0.9+ Fix from $1,9502024-09-04 CRITICAL 9.8 CVE-2024-7950 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitr… Wp Job Portal 2.1.7+ Fix from $2,3002024-09-04 CRITICAL 9.8 CVE-2024-45307 SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is … Sudobot 9.26.7+ Fix from $2,3002024-09-03 CRITICAL 9.8 CVE-2024-4259 Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatService) allows Collect Data as Pro… Akos after 2024-09-02 Fix from $2,3002024-09-03 MEDIUM 6.3 CVE-2024-7858 The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the… Media Library Folders 8.2.4+ Fix from $1,6002024-08-30 HIGH 7.1 CVE-2024-5784 The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple… Tutor Lms 2.7.3+ Fix from $1,9502024-08-30 MEDIUM 6.5 CVE-2024-43939 Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constrained by ACLs.This issue affe… Zynith after 7.4.9 Fix from $1,6002024-08-29 MEDIUM 6.5 CVE-2024-43940 Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constrained by ACLs.This issue affe… Zynith after 7.4.9 Fix from $1,6002024-08-29 HIGH 8.1 CVE-2024-7856EPSS 19% The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due … Mp3 Audio Player For Music\, Radio \& Podcast 5.7.1+ Fix from $1,9502024-08-29 CRITICAL 9.8 CVE-2024-4428 Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect… Managment Portal after 21.05.2024 Fix from $2,3002024-08-29 MEDIUM 5.3 CVE-2024-5857 The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorize… Funnelforms Free 3.7.4.1+ Fix from $1,6002024-08-29 MEDIUM 6.1 CVE-2024-41918 'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in h… Ichiba after 12.4.0 Fix from $1,6002024-08-29 HIGH 8.1 CVE-2024-45058 i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to… I Educar after 2.9 Fix from $1,9502024-08-28 MEDIUM 6.7 CVE-2024-20413 A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges t… Mitigation only Fix from $1,6002024-08-28 MEDIUM 5.3 CVE-2024-8195 The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', '… Permalink Manager Lite 2.4.4.1+ Fix from $1,6002024-08-28 MEDIUM 5.3 CVE-2024-7447 The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorize… Funnelforms Free 3.7.4.1+ Fix from $1,6002024-08-28 MEDIUM 5.3 CVE-2024-43214 Missing Authorization vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2. Mycred after 2.7.3 Fix from $1,6002024-08-26 HIGH 8.8 CVE-2024-7258 The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_r… Woocommerce Google Feed Manager 2.9.0+ Fix from $1,9502024-08-23 CRITICAL 9.8 CVE-2024-43331 Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3. Wp Sms 6.9.4+ Fix from $2,3002024-08-22 CRITICAL 9.1 CVE-2024-45168 An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism… Idol2 after 2.12 Fix from $2,3002024-08-22 MEDIUM 5.3 CVE-2024-7390 The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTest… Wp Testimonial Widget after 3.1 Fix from $1,6002024-08-21 MEDIUM 6.5 CVE-2024-7032 The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'moo_deact… Smart Online Order For Clover 1.5.7+ Fix from $1,6002024-08-21 HIGH 7.5 CVE-2024-38810 Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective. Spring Security 6.3.2+ Fix from $1,9502024-08-20 MEDIUM 5.4 CVE-2024-5941 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing… Givewp 3.14.2+ Fix from $1,6002024-08-20 MEDIUM 5.3 CVE-2024-5939 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… Givewp 3.14.0+ Fix from $1,6002024-08-20 MEDIUM 5.3 CVE-2024-5940 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… Givewp 3.14.0+ Fix from $1,6002024-08-20 MEDIUM 5.4 CVE-2024-43326 Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affe… Mitigation only Fix from $1,6002024-08-19 HIGH 7.1 CVE-2024-43256 Missing Authorization vulnerability in nouthemes Leopard - WordPress offload media allows Accessing Functionality Not Properly Constrained by ACLs.Th… Mitigation only Fix from $1,9502024-08-19