Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.3 CVE-2024-41624 Incorrect access control in Himalaya Xiaoya nano smart speaker rom_version 1.6.96 allows a remote attacker to have an unspecified impact. Mitigation only Fix from $1,6002024-07-29 MEDIUM 6.4 CVE-2024-6458 The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on th… Woocommerce Product Table 3.8.6+ Fix from $1,6002024-07-27 MEDIUM 5.8 CVE-2024-6591 The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check… Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.4 CVE-2024-4410 The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is d… Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.3 CVE-2024-1798 The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_ex… Tutor Lms Migration Tool after 2.2.2 Fix from $1,6002024-07-27 MEDIUM 6.5 CVE-2024-5861 The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the… Wp Easypay 4.2.4+ Fix from $1,6002024-07-24 MEDIUM 5.3 CVE-2024-6755 The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw… Social Auto Poster 5.3.15+ Fix from $1,6002024-07-24 HIGH 7.5 CVE-2024-6750 The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on… Social Auto Poster 5.3.15+ Fix from $1,9502024-07-24 CRITICAL 9.8 CVE-2024-6806 The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remo… Veristand after 2024 Fix from $2,3002024-07-22 CRITICAL 9.8 CVE-2024-6805 The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result i… Veristand after 2024 Fix from $2,3002024-07-22 CRITICAL 9.8 CVE-2024-6636 The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_… Woocommerce Social Login 2.7.4+ Fix from $2,3002024-07-20 MEDIUM 5.3 CVE-2024-6489 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_go… Getwid after 2.0.10 Fix from $1,6002024-07-20 MEDIUM 6.5 CVE-2023-7268 The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated user… Artplacer Widget after 2.21.1 Fix from $1,6002024-07-19 MEDIUM 5.3 CVE-2024-6455 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a miss… Elements Kit Elementor Addons 3.2.1+ Fix from $1,6002024-07-18 MEDIUM 5.4 CVE-2024-6175 The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… Mitigation only Fix from $1,6002024-07-18 HIGH 8.8 CVE-2024-6660 The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized modification o… Bookingpress 1.1.6+ Fix from $1,9502024-07-17 MEDIUM 6.5 CVE-2024-1937 The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_ite… Brizy 2.4.45+ Fix from $1,6002024-07-16 MEDIUM 6.5 CVE-2024-37202 Missing Authorization vulnerability in BinaryCarpenter Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter custom-add-to-ca… Mitigation only Fix from $1,6002024-07-12 CRITICAL 9.8 CVE-2024-6328 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and… Mstore Api 4.15.0+ Fix from $2,3002024-07-12 MEDIUM 5.4 CVE-2024-6392 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability… Sirv 7.2.8+ Fix from $1,6002024-07-11 HIGH 7.3 CVE-2024-39546 A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticate… Junos Os Evolved Mitigation only Fix from $1,9502024-07-11 MEDIUM 5.3 CVE-2024-0619 The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the payment_… Payment Gateway after 2.5.0 Fix from $1,6002024-07-11 MEDIUM 5.3 CVE-2024-38353 CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability … Codimd 2.5.4+ Fix from $1,6002024-07-10 HIGH 8.8 CVE-2024-21417 Windows Text Services Framework Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.6054 / 10.0.19044.4651+ Fix from $1,9502024-07-10 HIGH 7.8 CVE-2024-31318 In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. … Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31332 In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. This could … Android Patch available Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-6069 The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for… Mitigation only Fix from $1,9502024-07-09 MEDIUM 6.5 CVE-2024-5992 The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_chatbo… Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.4 CVE-2024-5993 The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_sessio… Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.4 CVE-2024-5648 The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several func… Mitigation only Fix from $1,6002024-07-09