Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2024-5669
The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthorized modification of data due…
Mitigation only
MEDIUM 5.4
CVE-2024-5600
The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing …
No fix yet
MEDIUM 5.3
CVE-2024-3608
The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_d…
Mitigation only
MEDIUM 5.4
CVE-2024-4102
The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all v…
Mitigation only
HIGH 7.2
CVE-2024-6180
The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings…
Mitigation only
MEDIUM 5.4
CVE-2024-37172
SAP S/4HANA Finance (Advanced Payment
Management) does not perform necessary authorization check for an authenticated
user, resulting in escalation o…
S4core
Mitigation only
MEDIUM 6.5
CVE-2024-37175
SAP CRM WebClient does not
perform necessary authorization check for an authenticated user, resulting in
escalation of privileges. This could allow a…
Customer Relationship Management S4fnd
Mitigation only
MEDIUM 6.5
CVE-2024-39592
Elements of PDCE does not perform necessary
authorization checks for an authenticated user, resulting in escalation of
privileges.
This
allows an …
S4core
Mitigation only
MEDIUM 6.5
CVE-2024-4341
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by U…
Extreme Xds
3928+
MEDIUM 6.3
CVE-2024-37542
Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: f…
Gallery
after 2.0.3
HIGH 8.2
CVE-2024-37903
Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific …
Mastodon
4.1.18 / 4.2.10+
MEDIUM 5.4
CVE-2024-5641
The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_oc…
One Click Order Re Order
1.1.10+
MEDIUM 6.5
CVE-2024-36113
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version…
Discourse
3.2.3 / 3.3.0+
MEDIUM 5.3
CVE-2024-6088
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the '…
Learnpress
4.2.6.8.2+
MEDIUM 5.3
CVE-2024-5545
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch…
Motors Car Dealer\, Classifieds \& Listing
1.4.11+
MEDIUM 6.5
CVE-2024-6375
A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to ei…
MongoDB
5.0.22 / 6.0.11+
MEDIUM 6.5
CVE-2024-5570
The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated …
Simple Photoswipe
after 0.1
MEDIUM 5.4
CVE-2024-5863
The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_image_collage() …
Mitigation only
CRITICAL 10.0
CVE-2024-6071
PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS command…
Mitigation only
HIGH 8.8
CVE-2024-5820
An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend a…
Devika
No fix yet
MEDIUM 6.5
CVE-2024-5710
berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to…
Litellm
No fix yet
CRITICAL 9.3
CVE-2024-2882
SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. This breach could potentially …
Mitigation only
HIGH 8.8
CVE-2024-6303
Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for …
Conduit
0.8.0+
HIGH 7.5
CVE-2024-37111
Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.
Wishlist Member X
after 3.26.7
MEDIUM 6.5
CVE-2024-6120
The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on…
Sparkle Demo Importer
1.4.8+
HIGH 8.8
CVE-2022-45803
Missing Authorization vulnerability in Nikolay Strikhar WordPress Form Builder Plugin – Gutenberg Forms.This issue affects WordPress Form Builder Plu…
Gutenberg Forms
2.2.9+
HIGH 8.8
CVE-2023-51375
Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.
Embedpress
3.8.4+
HIGH 8.8
CVE-2022-43453
Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41.
Wp Tools
3.43+
MEDIUM 5.3
CVE-2024-3961
The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of …
Convertkit Email Marketing\, Email Newsletter And Landing Pages
2.4.9.1+
MEDIUM 6.5
CVE-2024-1639
The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLi…
License Manager For Woocommerce
after 3.0.7