Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.8 CVE-2024-25912 Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. No fix yet Fix from $2,3002024-04-11 MEDIUM 5.4 CVE-2024-25922 Missing Authorization vulnerability in Peach Payments Peach Payments Gateway.This issue affects Peach Payments Gateway: from n/a through 3.1.9. Mitigation only Fix from $1,6002024-04-11 MEDIUM 5.3 CVE-2024-24850 Missing Authorization vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from… No fix yet Fix from $1,6002024-04-11 HIGH 7.5 CVE-2023-51672 Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3. Mitigation only Fix from $1,9502024-04-11 MEDIUM 5.4 CVE-2023-27607 Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a t… No fix yet Fix from $1,6002024-04-11 MEDIUM 6.5 CVE-2022-44633 Missing Authorization vulnerability in YITH YITH WooCommerce Gift Cards Premium.This issue affects YITH WooCommerce Gift Cards Premium: from n/a thro… Mitigation only Fix from $1,6002024-04-11 HIGH 8.8 CVE-2024-31997EPSS 74% XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as V… Xwiki 14.10.19 / 15.5.4+ Fix from $1,9502024-04-10 HIGH 8.8 CVE-2024-31987 XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who ca… Xwiki 14.10.19 / 15.5.4+ Fix from $1,9502024-04-10 HIGH 8.8 CVE-2024-31981 XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code execution is … Xwiki 14.10.19 / 15.5.4+ Fix from $1,9502024-04-10 HIGH 8.8 CVE-2024-31983 XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit right, circumventing the rights… Xwiki 14.10.20 / 15.5.4+ Fix from $1,9502024-04-10 MEDIUM 5.3 CVE-2024-31230 Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images… Mitigation only Fix from $1,6002024-04-10 MEDIUM 5.3 CVE-2024-31242 Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. No fix yet Fix from $1,6002024-04-10 MEDIUM 6.5 CVE-2024-31342 Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Exporter: from n/a through 1.3. Mitigation only Fix from $1,6002024-04-10 HIGH 7.5 CVE-2024-31343 Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Mus… Mp3 Audio Player For Music\, Radio \& Podcast 5.0+ Fix from $1,9502024-04-10 MEDIUM 5.3 CVE-2024-31297 Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0. Wholesale For Woocommerce after 2.3.0 Fix from $1,6002024-04-10 HIGH 7.5 CVE-2024-31358 Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel:… Mitigation only Fix from $1,9502024-04-10 MEDIUM 5.3 CVE-2024-3235 The Essential Grid Gallery WordPress Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… Mitigation only Fix from $1,6002024-04-10 MEDIUM 5.4 CVE-2024-1042 The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to… Wp Radio after 3.1.9 Fix from $1,6002024-04-10 MEDIUM 5.4 CVE-2024-1041 The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… Wp Radio after 3.1.9 Fix from $1,6002024-04-10 HIGH 8.2 CVE-2024-3213 The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rel… Relevanssi 4.22.2+ Fix from $1,9502024-04-09 MEDIUM 5.3 CVE-2024-3097EPSS 38% The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on… Nextgen Gallery 3.59.1+ Fix from $1,6002024-04-09 MEDIUM 5.3 CVE-2024-1984 The Graphene theme for WordPress is vulnerable to unauthorized access of data via meta tag in all versions up to, and including, 2.9.2. This makes it… Mitigation only Fix from $1,6002024-04-09 HIGH 8.8 CVE-2024-1991 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalat… Registrationmagic 5.3.1.0+ Fix from $1,9502024-04-09 MEDIUM 6.3 CVE-2024-1850 The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized access, modification or deletion of posts due to a missing capa… Mitigation only Fix from $1,6002024-04-09 HIGH 7.5 CVE-2024-1934 The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'w… Wp Compress 6.11.11+ Fix from $1,9502024-04-09 MEDIUM 5.3 CVE-2024-1587 The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via the 'newsmatic_filt… Newsmatic 1.3.5+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-1641 The Accordion plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'ac… Mitigation only Fix from $1,6002024-04-09 MEDIUM 5.3 CVE-2024-1352 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data … Classified Listing 3.0.5+ Fix from $1,6002024-04-09 HIGH 7.1 CVE-2024-31367 Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. Soledad 8.4.6+ Fix from $1,9502024-04-09 MEDIUM 6.5 CVE-2024-31368 Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. Soledad 8.4.6+ Fix from $1,6002024-04-09