Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.1 CVE-2024-25929 Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX.This issue affects Product Catalog Enquir… Product Catalog Mode For Woocommerce 5.0.6+ Fix from $2,3002024-06-09 HIGH 8.8 CVE-2023-23640 Missing Authorization vulnerability in MainWP MainWP UpdraftPlus Extension.This issue affects MainWP UpdraftPlus Extension: from n/a through 4.0.6. Updraftplus Extension 4.0.7+ Fix from $1,9502024-06-09 HIGH 8.8 CVE-2023-31080 Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlim… Unlimited Elements For Elementor 1.5.66+ Fix from $1,9502024-06-09 HIGH 8.8 CVE-2023-23639 Missing Authorization vulnerability in MainWP MainWP Staging Extension.This issue affects MainWP Staging Extension: from n/a through 4.0.3. Staging Extension 4.0.4+ Fix from $1,9502024-06-09 HIGH 8.8 CVE-2024-31098 Missing Authorization vulnerability in Mr.Ebabi New Order Notification for Woocommerce.This issue affects New Order Notification for Woocommerce: fro… New Order Notification For Woocommerce after 2.0.2 Fix from $1,9502024-06-09 HIGH 8.8 CVE-2024-31246 Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a… Postx 3.2.4+ Fix from $1,9502024-06-09 HIGH 8.8 CVE-2024-31294 Missing Authorization vulnerability in Fahad Mahmood WP Sort Order.This issue affects WP Sort Order: from n/a through 1.3.1. Wp Sort Order 1.3.2+ Fix from $1,9502024-06-09 HIGH 8.8 CVE-2024-30537 Missing Authorization vulnerability in WPClever WPC Badge Management for WooCommerce.This issue affects WPC Badge Management for WooCommerce: from n/… Wpc Badge Management For Woocommerce 2.4.1+ Fix from $1,9502024-06-09 CRITICAL 9.8 CVE-2024-30538 Missing Authorization vulnerability in DELUCKS GmbH DELUCKS SEO.This issue affects DELUCKS SEO: from n/a through 2.5.4. Delucks Seo 2.5.5+ Fix from $2,3002024-06-09 CRITICAL 9.8 CVE-2024-30539 Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7. Awesome Support 6.1.8+ Fix from $2,3002024-06-09 MEDIUM 6.5 CVE-2023-52230 Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1… Booster For Woocommerce after 7.1.3 Fix from $1,6002024-06-09 MEDIUM 6.5 CVE-2023-52232 Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1… Booster For Woocommerce 7.1.2+ Fix from $1,6002024-06-09 CRITICAL 9.8 CVE-2024-30534 Missing Authorization vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: fro… Calendarista 3.0.6+ Fix from $2,3002024-06-09 CRITICAL 9.8 CVE-2023-51494 Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1. Product Vendors 2.2.2+ Fix from $2,3002024-06-09 MEDIUM 5.4 CVE-2024-21748 Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21. Icegram Express 3.1.22+ Fix from $1,6002024-06-08 MEDIUM 5.3 CVE-2024-22151 Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from… Import And Export Users And Customers 1.24.7+ Fix from $1,6002024-06-08 HIGH 8.8 CVE-2024-35659 Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Contr… Kivicare after 3.6.4 Fix from $1,9502024-06-08 MEDIUM 6.5 CVE-2024-5654 The CF7 Google Sheets Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'exe… Cf7 Google Sheets Connector 5.0.10+ Fix from $1,6002024-06-08 MEDIUM 5.4 CVE-2024-4468 The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on seve… Salon Booking System 10.0+ Fix from $1,6002024-06-08 MEDIUM 5.4 CVE-2024-5087 The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … Minimal Coming Soon \& Maintenance Mode 2.39+ Fix from $1,6002024-06-08 MEDIUM 5.3 CVE-2024-5382 The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to unauthorized modi… Master Addons 2.0.6.2+ Fix from $1,6002024-06-07 HIGH 8.1 CVE-2024-5637 The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_files' function … Market Exporter 2.0.20+ Fix from $1,9502024-06-07 MEDIUM 5.4 CVE-2024-5607 The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … Gdpr Ccpa Compliance \& Cookie Consent Banner 2.7.1+ Fix from $1,6002024-06-07 MEDIUM 5.4 CVE-2023-6876 The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … Clever Fox 25.2.1+ Fix from $1,6002024-06-07 MEDIUM 6.5 CVE-2024-5248 In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` en… Lunary 1.4.9+ Fix from $1,6002024-06-06 MEDIUM 6.5 CVE-2024-5126 An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating… Lunary 1.2.25+ Fix from $1,6002024-06-06 HIGH 8.2 CVE-2024-5129 A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization ch… Lunary 1.2.8+ Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-5130 An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete … Lunary 1.2.8+ Fix from $1,9502024-06-06 HIGH 8.1 CVE-2024-4888 BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on the `/audio/transcriptions` en… Litellm 1.35.19+ Fix from $1,9502024-06-06 MEDIUM 6.5 CVE-2024-2035 An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vuln… Zenml 0.56.2+ Fix from $1,6002024-06-06