Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2023-6751 The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_web… Hostinger after 1.9.7 Fix from $1,6002024-01-11 MEDIUM 5.3 CVE-2023-6637 The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… Complete Analytics Optimization Suite 4.7.15+ Fix from $1,6002024-01-11 MEDIUM 5.3 CVE-2023-6638 The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'u… Gg Woo Feed after 1.2.4 Fix from $1,6002024-01-11 MEDIUM 5.4 CVE-2023-6369 The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing cap… Export Wp Page To Static Html\/css after 2.1.9 Fix from $1,6002024-01-11 MEDIUM 5.3 CVE-2023-6496 The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_… Manage Notification E Mails 1.8.6+ Fix from $1,6002024-01-11 MEDIUM 6.5 CVE-2023-6158 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to… Eventon after 4.5.4 Fix from $1,6002024-01-10 CRITICAL 9.8 CVE-2023-48245 The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a cra… Nexo Os after 1500-sp2 Fix from $2,3002024-01-10 HIGH 7.5 CVE-2023-48247 The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application OS user (“root”) via a craft… Nexo Os after 1500-sp2 Fix from $1,9502024-01-10 HIGH 8.8 CVE-2022-34344 Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Ro… Wholesale Suite after 2.1.5 Fix from $1,9502024-01-08 HIGH 8.8 CVE-2022-36352 Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – … Profilegrid after 5.0.3 Fix from $1,9502024-01-08 HIGH 7.5 CVE-2023-6383 The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug… Debug Log Manager 2.3.0+ Fix from $1,9502024-01-08 MEDIUM 5.4 CVE-2023-6798 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized s… Rss Aggregator By Feedzy 4.3.3+ Fix from $1,6002024-01-06 MEDIUM 6.5 CVE-2023-6733 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via… Wp Members after 3.4.8 Fix from $1,6002024-01-04 MEDIUM 6.5 CVE-2023-7068 The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due… Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels 4.3.1+ Fix from $1,6002024-01-03 HIGH 7.7 CVE-2023-42358 An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial of service … Ric Plt E2mgr No fix yet Fix from $1,9502024-01-03 MEDIUM 5.4 CVE-2023-6600 The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-… Omgf 5.7.10+ Fix from $1,6002024-01-03 MEDIUM 5.5 CVE-2023-4164 There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no … Android Mitigation only Fix from $1,6002024-01-02 CRITICAL 9.8 CVE-2023-47458 An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework. Springblade after 3.7.0 Fix from $2,3002024-01-02 CRITICAL 9.8 CVE-2023-5877 The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_… Affiliate Toolkit 3.4.3+ Fix from $2,3002024-01-01 HIGH 7.6 CVE-2023-4468 A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the compo… Trio 8800 Firmware Mitigation only Fix from $1,9502023-12-29 HIGH 8.8 CVE-2023-22676 Missing Authorization vulnerability in Anders Thorborg.This issue affects Anders Thorborg: from n/a through 1.4.12. Advanced Custom Fields\ after 1.4.12 Fix from $1,9502023-12-29 HIGH 8.8 CVE-2023-49230 An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals'… Balance Two Firmware 8.4.0+ Fix from $1,9502023-12-28 MEDIUM 5.3 CVE-2023-49003 An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interaction with com.simplemobiletoo… Simple Dialer No fix yet Fix from $1,6002023-12-27 HIGH 7.5 CVE-2023-51650 Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized acc… Hertzbeat 1.4.1+ Fix from $1,9502023-12-22 HIGH 8.8 CVE-2023-22674 Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + C… Dashicons \+ Custom Post Types after 1.0.2 Fix from $1,9502023-12-21 MEDIUM 6.5 CVE-2023-25715 Missing Authorization vulnerability in GamiPress GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress.T… Gamipress after 2.5.6 Fix from $1,6002023-12-19 HIGH 8.8 CVE-2023-46212 Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionality Not Properly Constrained by… Wp Extra after 6.2 Fix from $1,9502023-12-19 CRITICAL 9.8 CVE-2023-47754 Missing Authorization vulnerability in Clever plugins Delete Duplicate Posts allows Accessing Functionality Not Properly Constrained by ACLs.This iss… Delete Duplicate Posts after 4.8.9 Fix from $2,3002023-12-19 HIGH 8.8 CVE-2023-48751 Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functi… Participants Database after 2.5.5 Fix from $1,9502023-12-19 HIGH 7.5 CVE-2023-5949 The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content. Smartcrawl 3.8.3+ Fix from $1,9502023-12-18