Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.1 CVE-2024-23388 Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a… Mercari 5.78.0+ Fix from $1,6002024-01-26 MEDIUM 5.3 CVE-2023-5612 An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read … GitLab 16.6.6 / 16.7.4+ Fix from $1,6002024-01-26 MEDIUM 5.3 CVE-2024-0617 The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp… Category Discount Woocommerce 4.13+ Fix from $1,6002024-01-25 MEDIUM 6.5 CVE-2023-50944 Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't … Airflow 2.8.1+ Fix from $1,6002024-01-24 CRITICAL 9.8 CVE-2024-23752 GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python … Pandasai after 1.5.17 Fix from $2,3002024-01-22 MEDIUM 6.5 CVE-2024-0679 The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in a… Colormag after 3.1.2 Fix from $1,6002024-01-20 HIGH 8.8 CVE-2022-42884 Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a through 1.2.7. Wip Custom Login after 1.2.7 Fix from $1,9502024-01-17 CRITICAL 9.8 CVE-2022-41786 Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: fr… Wp Job Portal after 2.0.1 Fix from $2,3002024-01-17 HIGH 8.8 CVE-2022-41790 Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76. Wp Time Slots Booking Form after 1.1.76 Fix from $1,9502024-01-17 HIGH 8.8 CVE-2023-23896 Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0… Url Shortener after 1.0.17 Fix from $1,9502024-01-17 MEDIUM 6.5 CVE-2022-41619 Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8. Image Zoom after 1.8.8 Fix from $1,6002024-01-17 MEDIUM 6.5 CVE-2022-41695 Missing Authorization vulnerability in SedLex Traffic Manager.This issue affects Traffic Manager: from n/a through 1.4.5. Traffic Manager after 1.4.5 Fix from $1,6002024-01-17 MEDIUM 6.5 CVE-2022-38141 Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a throu… Sales Report Email For Woocommerce after 2.8 Fix from $1,6002024-01-17 HIGH 8.8 CVE-2022-40203 Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce… Advanced Dynamic Pricing For Woocommerce 4.1.6+ Fix from $1,9502024-01-17 CRITICAL 9.8 CVE-2022-36418 Missing Authorization vulnerability in Vagary Digital HREFLANG Tags Lite.This issue affects HREFLANG Tags Lite: from n/a through 2.0.0. Hreflang Tags Lite after 2.0.0 Fix from $2,3002024-01-17 MEDIUM 5.3 CVE-2023-48926 An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily chang… Advanced Loyalty Program 2.3.4+ Fix from $1,6002024-01-16 MEDIUM 5.3 CVE-2024-0235EPSS 38% The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticate… Eventon 2.2.7 / 4.5.5+ Fix from $1,6002024-01-16 MEDIUM 5.3 CVE-2024-0236 The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticate… Eventon 2.2.7 / 4.5.5+ Fix from $1,6002024-01-16 MEDIUM 5.3 CVE-2024-0237 The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenti… Eventon 2.2.7 / 4.5.5+ Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2024-0238 The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not en… Eventon 2.2.7 / 4.5.5+ Fix from $1,6002024-01-16 CRITICAL 9.1 CVE-2024-0570 A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi… N350rt Firmware Mitigation only Fix from $2,3002024-01-16 CRITICAL 9.1 CVE-2024-0569 A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /… T8 Firmware No fix yet Fix from $2,3002024-01-16 HIGH 8.3 CVE-2023-34063 Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauth… Aria Automation Patch available Fix from $1,9502024-01-16 HIGH 8.1 CVE-2023-5905 The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog … Export Posts With Images after 20220825 Fix from $1,9502024-01-15 HIGH 7.5 CVE-2023-6029 The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are docu… Eazydocs 2.3.6+ Fix from $1,9502024-01-15 MEDIUM 6.5 CVE-2023-6048 The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting an… Estatik 4.1.1+ Fix from $1,6002024-01-15 MEDIUM 5.3 CVE-2023-6955 A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7… GitLab 16.5.6 / 16.6.4+ Fix from $1,6002024-01-12 MEDIUM 6.5 CVE-2023-6554 When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to d… Tcexam 15.1.0+ Fix from $1,6002024-01-11 MEDIUM 5.3 CVE-2023-6855 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modificati… Paid Memberships Pro after 2.12.5 Fix from $1,6002024-01-11 CRITICAL 9.8 CVE-2023-6875EPSS 90% The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized … Post Smtp after 2.8.7 Fix from $2,3002024-01-11