Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2023-34234 OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer a… Contracts 4.9.1+ Fix from $1,6002023-06-07 HIGH 8.8 CVE-2021-4337 Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax… Add Product Tabs 1.3.0 / 1.5.0+ Fix from $1,9502023-06-07 MEDIUM 6.5 CVE-2021-4379 The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmc_bulk_fixed_pri… Woocommerce Multi Currency 2.1.18+ Fix from $1,6002023-06-07 MEDIUM 6.5 CVE-2023-3125 The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'b2bking_save_price_impo… B2bking after 4.6.00 Fix from $1,6002023-06-07 CRITICAL 9.8 CVE-2021-4374EPSS 16% The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to miss… Wordpress Automatic Plugin after 3.53.2 Fix from $2,3002023-06-07 CRITICAL 9.8 CVE-2021-4381 The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, … Ulisting 1.7+ Fix from $2,3002023-06-07 HIGH 8.8 CVE-2022-4950 Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execu… Cool Timeline 1.2 / 1.3+ Fix from $1,9502023-06-07 HIGH 8.8 CVE-2023-3124EPSS 23% The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option fu… Elementor Pro 3.11.7+ Fix from $1,9502023-06-07 CRITICAL 9.8 CVE-2021-4356 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. Thi… Frontend File Manager Plugin after 18.2 Fix from $2,3002023-06-07 MEDIUM 5.3 CVE-2021-4357 The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the Ulisti… Ulisting after 1.6.6 Fix from $1,6002023-06-07 MEDIUM 5.3 CVE-2021-4359 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This … Frontend File Manager Plugin after 18.2 Fix from $1,6002023-06-07 HIGH 8.8 CVE-2021-4361 The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrat… Jobsearch Wp Job Board after 1.8.1 Fix from $1,9502023-06-07 CRITICAL 9.8 CVE-2021-4362 The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_optio… Kiwi Social Share No fix yet Fix from $2,3002023-06-07 HIGH 8.8 CVE-2021-4368 The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to … Frontend File Manager Plugin after 18.2 Fix from $1,9502023-06-07 MEDIUM 5.3 CVE-2021-4369 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due… Frontend File Manager Plugin after 18.2 Fix from $1,6002023-06-07 CRITICAL 9.8 CVE-2021-4370 The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack s… Ulisting after 1.6.6 Fix from $2,3002023-06-07 MEDIUM 5.3 CVE-2021-4339 The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file o… Ulisting after 1.6.6 Fix from $1,6002023-06-07 CRITICAL 9.8 CVE-2021-4341 The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a mi… Ulisting after 1.6.6 Fix from $2,3002023-06-07 CRITICAL 9.8 CVE-2021-4343 The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. … Ulisting after 1.6.6 Fix from $2,3002023-06-07 MEDIUM 5.3 CVE-2021-4345 The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role… Ulisting after 1.6.6 Fix from $1,6002023-06-07 HIGH 7.5 CVE-2021-4346 The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to … Ulisting after 1.6.6 Fix from $1,9502023-06-07 MEDIUM 6.5 CVE-2021-4347 The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable t… Advanced Shipment Tracking For Woocommerce after 3.2.6 Fix from $1,6002023-06-07 MEDIUM 6.1 CVE-2021-4348 The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export_settings & import_settings f… Ultimate Gdpr \& Ccpa Compliance Toolkit 2.5+ Fix from $1,6002023-06-07 MEDIUM 5.3 CVE-2021-4350 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to… Frontend File Manager Plugin after 18.2 Fix from $1,6002023-06-07 MEDIUM 5.3 CVE-2021-4351 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due … Frontend File Manager Plugin after 18.2 Fix from $1,6002023-06-07 MEDIUM 5.3 CVE-2021-4355 The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list()… Welcart E Commerce after 2.2.7 Fix from $1,6002023-06-07 CRITICAL 9.8 CVE-2020-36719 The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in ver… Listingpro after 2.6.1 Fix from $2,3002023-06-07 HIGH 7.1 CVE-2020-36720 The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_… Kali Forms after 2.1.1 Fix from $1,9502023-06-07 MEDIUM 6.5 CVE-2020-36721 The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is … Activello 1.0.6 / 1.1.2+ Fix from $1,6002023-06-07 HIGH 8.1 CVE-2020-36725 The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to… Ti Woocommerce Wishlist 1.21.5 / 1.21.12+ Fix from $1,9502023-06-07