Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.4 CVE-2024-5669 The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthorized modification of data due… Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.4 CVE-2024-5600 The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing … No fix yet Fix from $1,6002024-07-09 MEDIUM 5.3 CVE-2024-3608 The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_d… Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.4 CVE-2024-4102 The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all v… Mitigation only Fix from $1,6002024-07-09 HIGH 7.2 CVE-2024-6180 The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings… Mitigation only Fix from $1,9502024-07-09 MEDIUM 5.4 CVE-2024-37172 SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation o… S4core Mitigation only Fix from $1,6002024-07-09 MEDIUM 6.5 CVE-2024-37175 SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow a… Customer Relationship Management S4fnd Mitigation only Fix from $1,6002024-07-09 MEDIUM 6.5 CVE-2024-39592 Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an … S4core Mitigation only Fix from $1,6002024-07-09 MEDIUM 6.5 CVE-2024-4341 Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by U… Extreme Xds 3928+ Fix from $1,6002024-07-08 MEDIUM 6.3 CVE-2024-37542 Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: f… Gallery after 2.0.3 Fix from $1,6002024-07-06 HIGH 8.2 CVE-2024-37903 Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific … Mastodon 4.1.18 / 4.2.10+ Fix from $1,9502024-07-05 MEDIUM 5.4 CVE-2024-5641 The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_oc… One Click Order Re Order 1.1.10+ Fix from $1,6002024-07-04 MEDIUM 6.5 CVE-2024-36113 Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version… Discourse 3.2.3 / 3.3.0+ Fix from $1,6002024-07-03 MEDIUM 5.3 CVE-2024-6088 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the '… Learnpress 4.2.6.8.2+ Fix from $1,6002024-07-02 MEDIUM 5.3 CVE-2024-5545 The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… Motors Car Dealer\, Classifieds \& Listing 1.4.11+ Fix from $1,6002024-07-02 MEDIUM 6.5 CVE-2024-6375 A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to ei… MongoDB 5.0.22 / 6.0.11+ Fix from $1,6002024-07-01 MEDIUM 6.5 CVE-2024-5570 The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated … Simple Photoswipe after 0.1 Fix from $1,6002024-06-28 MEDIUM 5.4 CVE-2024-5863 The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_image_collage() … Mitigation only Fix from $1,6002024-06-28 CRITICAL 10.0 CVE-2024-6071 PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS command… Mitigation only Fix from $2,3002024-06-27 HIGH 8.8 CVE-2024-5820 An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend a… Devika No fix yet Fix from $1,9502024-06-27 MEDIUM 6.5 CVE-2024-5710 berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to… Litellm No fix yet Fix from $1,6002024-06-27 CRITICAL 9.3 CVE-2024-2882 SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. This breach could potentially … Mitigation only Fix from $2,3002024-06-27 HIGH 8.8 CVE-2024-6303 Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for … Conduit 0.8.0+ Fix from $1,9502024-06-25 HIGH 7.5 CVE-2024-37111 Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7. Wishlist Member X after 3.26.7 Fix from $1,9502024-06-24 MEDIUM 6.5 CVE-2024-6120 The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on… Sparkle Demo Importer 1.4.8+ Fix from $1,6002024-06-22 HIGH 8.8 CVE-2022-45803 Missing Authorization vulnerability in Nikolay Strikhar WordPress Form Builder Plugin – Gutenberg Forms.This issue affects WordPress Form Builder Plu… Gutenberg Forms 2.2.9+ Fix from $1,9502024-06-21 HIGH 8.8 CVE-2023-51375 Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3. Embedpress 3.8.4+ Fix from $1,9502024-06-21 HIGH 8.8 CVE-2022-43453 Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41. Wp Tools 3.43+ Fix from $1,9502024-06-21 MEDIUM 5.3 CVE-2024-3961 The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of … Convertkit Email Marketing\, Email Newsletter And Landing Pages 2.4.9.1+ Fix from $1,6002024-06-21 MEDIUM 6.5 CVE-2024-1639 The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLi… License Manager For Woocommerce after 3.0.7 Fix from $1,6002024-06-21