Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2024-43247 Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WHMpres… Mitigation only Fix from $1,9502024-08-19 HIGH 8.0 CVE-2024-43401 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can … Xwiki after 15.9 Fix from $1,9502024-08-19 HIGH 7.5 CVE-2024-44069 Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier rep… Pi Hole 6.0+ Fix from $1,9502024-08-19 MEDIUM 5.3 CVE-2024-35686 Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through… Mitigation only Fix from $1,6002024-08-18 MEDIUM 5.3 CVE-2023-4730 The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function … Mitigation only Fix from $1,6002024-08-17 MEDIUM 5.3 CVE-2023-4024 The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player funct… Radio Player 2.0.74+ Fix from $1,6002024-08-17 MEDIUM 5.3 CVE-2023-4025 The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player funct… Radio Player 2.0.74+ Fix from $1,6002024-08-17 MEDIUM 5.3 CVE-2023-4027 The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings fun… Radio Player after 2.0.73 Fix from $1,6002024-08-17 CRITICAL 10.0 CVE-2024-6500 The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capa… Mitigation only Fix from $2,3002024-08-17 HIGH 7.5 CVE-2024-38699 Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This i… Mitigation only Fix from $1,9502024-08-13 HIGH 7.5 CVE-2024-37935 Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects… Mitigation only Fix from $1,9502024-08-13 MEDIUM 5.3 CVE-2024-39591 SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing lo… Document Builder Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.4 CVE-2024-42373 SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of… Student Life Cycle Management Mitigation only Fix from $1,6002024-08-13 MEDIUM 6.5 CVE-2024-42376 SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On succ… Shared Service Framework Mitigation only Fix from $1,6002024-08-13 CRITICAL 9.8 CVE-2024-41730EPSS 76% In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a lo… Business Objects Business Intelligence Platform Mitigation only Fix from $2,3002024-08-13 MEDIUM 6.3 CVE-2024-33005 Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java)… Netweaver Abap Mitigation only Fix from $1,6002024-08-13 HIGH 7.5 CVE-2024-37930 Insertion of Sensitive Information into Log File vulnerability in ThemeSphere SmartMag smartmag-responsive-retina-wordpress-magazine.This issue affec… Smartmag after 9.3.0 Fix from $1,9502024-08-12 MEDIUM 5.4 CVE-2024-7621 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due … Mitigation only Fix from $1,6002024-08-12 HIGH 7.5 CVE-2024-6760 A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivile… FreeBSD 13.0 / 13.3+ Fix from $1,9502024-08-12 CRITICAL 9.1 CVE-2024-42470 openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Several endpoints in versions … Openhab 4.2.1+ Fix from $2,3002024-08-12 HIGH 7.8 CVE-2024-42035 Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confi… Emui No fix yet Fix from $1,9502024-08-08 HIGH 7.1 CVE-2024-6869 The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on s… Falang 1.3.53+ Fix from $1,9502024-08-08 MEDIUM 6.3 CVE-2024-43045 Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read perm… Jenkins 2.452.4 / 2.471+ Fix from $1,6002024-08-07 MEDIUM 5.4 CVE-2024-6872 The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for Elementor & Gutenberg Blocks!… Templatespare 2.4.3+ Fix from $1,6002024-08-03 HIGH 8.8 CVE-2024-7031 The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt… Filester 1.8.3+ Fix from $1,9502024-08-03 HIGH 8.8 CVE-2024-6698 The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not … Fundengine 1.7.1+ Fix from $1,9502024-08-01 MEDIUM 5.9 CVE-2024-41108 FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only … Fogproject 1.5.10.41+ Fix from $1,6002024-07-31 HIGH 8.8 CVE-2024-37901 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can per… Xwiki 14.10.21 / 15.5.5+ Fix from $1,9502024-07-31 MEDIUM 6.5 CVE-2024-7135 The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all ve… Tainacan 0.21.8+ Fix from $1,6002024-07-31 MEDIUM 5.3 CVE-2024-2508 The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_menu_item_ic… Mitigation only Fix from $1,6002024-07-31