Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2024-0780 The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing a… Enjoy Social Feed after 6.2.2 Fix from $1,9502024-03-18 HIGH 8.2 CVE-2024-22257 In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6… Mitigation only Fix from $1,9502024-03-18 MEDIUM 5.3 CVE-2024-1857 The Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates plugin for WordPress is vulne… Mitigation only Fix from $1,6002024-03-16 MEDIUM 5.3 CVE-2024-1733 The Word Replacer Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the word_replacer_… Word Replacer Pro Mitigation only Fix from $1,6002024-03-16 HIGH 8.8 CVE-2023-50898 Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2. Sirv after 7.1.2 Fix from $1,9502024-03-15 MEDIUM 5.3 CVE-2024-23944 Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by… Zookeeper 3.8.4 / 3.9.2+ Fix from $1,6002024-03-15 MEDIUM 6.5 CVE-2024-1862 The WooCommerce Add to Cart Custom Redirect plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing… Woocommerce Add To Cart Custom Redirect 1.2.14+ Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-1763 The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… Wp Social Login And Register Social Counter after 3.0.0 Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-1380EPSS 50% The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanss… Relevanssi 4.22.1+ Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-1176 The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… Ht Easy Ga4 1.2.0+ Fix from $1,6002024-03-13 MEDIUM 6.3 CVE-2024-0828 The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to unauthorized access of functionality du… Play.ht after 3.6.4 Fix from $1,6002024-03-13 HIGH 7.5 CVE-2024-0683 The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in … Bulgarisation For Woocommerce 3.0.15+ Fix from $1,9502024-03-13 MEDIUM 5.3 CVE-2024-0377 The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… Lifterlms 7.5.2+ Fix from $1,6002024-03-13 MEDIUM 5.0 CVE-2024-0447 The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … Artibot 1.1.7+ Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2023-6785 The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and includ… Download Manager 3.2.85+ Fix from $1,6002024-03-13 HIGH 7.5 CVE-2024-2107 The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.3 via generated source.… Blossom Spa 1.3.4+ Fix from $1,9502024-03-12 MEDIUM 5.4 CVE-2023-4728 The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function ho… Ladipage after 4.4 Fix from $1,6002024-03-12 MEDIUM 5.4 CVE-2024-1328 The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 4… Newsletter2go 4.0.14+ Fix from $1,6002024-03-12 MEDIUM 5.3 CVE-2024-27900 Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of jo… Abap Platform Mitigation only Fix from $1,6002024-03-12 MEDIUM 5.4 CVE-2024-1125 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ch… Eventprime 3.4.4+ Fix from $1,6002024-03-09 MEDIUM 6.5 CVE-2024-1123 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… Eventprime 3.4.3+ Fix from $1,6002024-03-09 MEDIUM 6.5 CVE-2024-1851 The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the… Affiliate Toolkit 3.5.5+ Fix from $1,6002024-03-08 MEDIUM 5.5 CVE-2024-23230 This issue was addressed with improved file handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app m… macOS 12.7.4 / 13.6.5+ Fix from $1,6002024-03-08 MEDIUM 6.5 CVE-2024-28230 In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions Youtrack 2024.1.25893+ Fix from $1,6002024-03-07 HIGH 8.2 CVE-2024-1170 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner… Post Form 2.8.8+ Fix from $1,9502024-03-07 HIGH 7.5 CVE-2024-1169 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner… Post Form 2.8.8+ Fix from $1,9502024-03-07 MEDIUM 5.4 CVE-2024-28216 nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of informa… Ngrinder 3.5.9+ Fix from $1,6002024-03-07 HIGH 7.5 CVE-2024-28215 nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of informa… Ngrinder 3.5.9+ Fix from $1,9502024-03-07 HIGH 8.8 CVE-2024-2216 A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to … Docker Build Step after 2.11 Fix from $1,9502024-03-06 MEDIUM 5.3 CVE-2024-1095 The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing cap… Build \& Control Block Pattern after 1.3.5.4 Fix from $1,6002024-03-05