Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2024-26138 The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the document `Licenses.Code.LicenseJSON`… Application Licensing 1.24.2+ Fix from $1,6002024-02-21 MEDIUM 5.3 CVE-2024-0593 The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick… Simple Job Board 2.11.0+ Fix from $1,6002024-02-21 MEDIUM 5.3 CVE-2024-1562 The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… Woocommerce Google Sheet Connector 1.3.12+ Fix from $1,6002024-02-21 HIGH 8.2 CVE-2024-1108 The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() funct… Plugin Groups 2.0.7+ Fix from $1,9502024-02-21 HIGH 7.8 CVE-2024-0038 In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission… Android Patch available Fix from $1,9502024-02-16 MEDIUM 5.5 CVE-2023-40105 In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could le… Android Patch available Fix from $1,6002024-02-15 MEDIUM 5.5 CVE-2023-40113 In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local… Android Patch available Fix from $1,6002024-02-15 MEDIUM 6.5 CVE-2023-26562 In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/s… Collaboration Mitigation only Fix from $1,6002024-02-13 MEDIUM 6.3 CVE-2024-24739 SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges w… Bank Account Management Mitigation only Fix from $1,6002024-02-13 MEDIUM 5.3 CVE-2024-0596 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili… Awesome Support 6.1.8+ Fix from $1,6002024-02-10 MEDIUM 5.3 CVE-2024-1122 The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to… Eventin 3.3.51+ Fix from $1,6002024-02-09 MEDIUM 6.7 CVE-2023-6840 An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allo… GitLab 16.6.7 / 16.7.5+ Fix from $1,6002024-02-07 CRITICAL 9.1 CVE-2024-24822 Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags withou… Admin Classic Bundle 1.3.3+ Fix from $2,3002024-02-07 MEDIUM 5.3 CVE-2024-1110 The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init()… Podlove Podcast Publisher after 4.0.11 Fix from $1,6002024-02-07 MEDIUM 5.3 CVE-2024-1109 The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_downloa… Podlove Podcast Publisher after 4.0.11 Fix from $1,6002024-02-07 MEDIUM 5.3 CVE-2024-1079 The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function… Quiz Maker 6.5.2.5+ Fix from $1,6002024-02-07 HIGH 7.5 CVE-2024-1072 The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unaut… Website Builder By Seedprod after 6.15.21 Fix from $1,9502024-02-05 MEDIUM 5.3 CVE-2024-1121 The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_json_fil… Advanced Forms For Acf after 1.9.3.2 Fix from $1,6002024-02-05 MEDIUM 5.3 CVE-2024-1177 The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… Wp Club Manager 2.2.11+ Fix from $1,6002024-02-05 MEDIUM 6.5 CVE-2024-0869 The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrar… Instant Images One Click Unsplash Uploads after 6.1.0 Fix from $1,6002024-02-05 HIGH 7.5 CVE-2024-0324 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized mod… Profile Builder after 3.10.8 Fix from $1,9502024-02-05 HIGH 8.8 CVE-2023-6985 The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… Ai Assistant 1.0.19+ Fix from $1,9502024-02-05 HIGH 8.8 CVE-2023-6700 The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check … Wp Gdpr Compliance after 2.0.22 Fix from $1,9502024-02-05 MEDIUM 5.3 CVE-2023-4637 The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_prog… Migration\, Backup\, Staging after 0.9.94 Fix from $1,6002024-02-05 MEDIUM 5.3 CVE-2023-6557 The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the ro… The Events Calendar after 6.2.8.2 Fix from $1,6002024-02-05 HIGH 7.5 CVE-2023-47148 IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper … Spectrum Protect Plus 10.1.15.3+ Fix from $1,9502024-02-02 MEDIUM 5.3 CVE-2024-1047 Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability c… Orbit Fox after 2.10.28 Fix from $1,6002024-02-02 MEDIUM 5.4 CVE-2023-22836 In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed… Guardian 2.278.0+ Fix from $1,6002024-01-29 HIGH 7.8 CVE-2023-1705 Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Fun… One Smartedge Agent 1.7.0.230330-554+ Fix from $1,9502024-01-29 HIGH 7.1 CVE-2023-6279 The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as sub… Sites Library 1.4.8+ Fix from $1,9502024-01-29