Total
4661 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-30467 | 1 Wpdeveloper | 1 Essential Blocks | 2024-11-21 | N/A | 6.5 MEDIUM |
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg.This issue affects Essential Blocks for Gutenberg: from n/a through 4.4.9. | |||||
CVE-2024-30466 | 1 Onthegosystems | 1 Woocommerce Multilingual \& Multicurrency | 2024-11-21 | N/A | 5.4 MEDIUM |
Missing Authorization vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.4. | |||||
CVE-2024-30465 | 1 Pagelayer | 1 Pagelayer | 2024-11-21 | N/A | 6.5 MEDIUM |
Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1. | |||||
CVE-2024-30464 | 1 Wpzoom | 1 Social Icons Widget | 2024-11-21 | N/A | 5.4 MEDIUM |
Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15. | |||||
CVE-2024-30459 | 2024-11-21 | N/A | 5.3 MEDIUM | ||
Missing Authorization vulnerability in AIpost AI WP Writer.This issue affects AI WP Writer: from n/a through 3.6.5. | |||||
CVE-2024-30217 | 2024-11-21 | N/A | 4.3 MEDIUM | ||
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting the integrity of the application. Confidentiality and Availability are not impacted. | |||||
CVE-2024-30216 | 2024-11-21 | N/A | 4.3 MEDIUM | ||
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of the application. Confidentiality and Availability are not impacted. | |||||
CVE-2024-2906 | 2024-11-21 | N/A | 6.5 MEDIUM | ||
Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |||||
CVE-2024-2882 | 2024-11-21 | N/A | N/A | ||
SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. This breach could potentially lead to unauthorized control, data manipulation, and access to sensitive information within the SCADA system. | |||||
CVE-2024-2702 | 2024-11-21 | N/A | 8.2 HIGH | ||
Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | |||||
CVE-2024-2544 | 1 Sygnoos | 1 Popup Builder | 2024-11-21 | N/A | 7.4 HIGH |
The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple unauthorized actions, such as deleting subscribers, and importing subscribers to conduct stored cross-site scripting attacks. | |||||
CVE-2024-2216 | 2024-11-21 | N/A | 8.8 HIGH | ||
A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions. | |||||
CVE-2024-2017 | 1 Edmonsoft | 1 Countdown Builder | 2024-11-21 | N/A | 5.4 MEDIUM |
The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and switchCountdown functions in all versions up to, and including, 2.7.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject PHP Objects and modify the status of countdowns. | |||||
CVE-2024-28216 | 2024-11-21 | N/A | 5.4 MEDIUM | ||
nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery. | |||||
CVE-2024-28215 | 2024-11-21 | N/A | 7.5 HIGH | ||
nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery. | |||||
CVE-2024-28167 | 2024-11-21 | N/A | 6.5 MEDIUM | ||
SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data can be changed via the Enter Package Data app although the user does not have sufficient authorization causing high impact on Integrity of the appliction. | |||||
CVE-2024-28159 | 2024-11-21 | N/A | 4.3 MEDIUM | ||
A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build. | |||||
CVE-2024-28003 | 2024-11-21 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in Megamenu Max Mega Menu.This issue affects Max Mega Menu: from n/a through 3.3. | |||||
CVE-2024-27970 | 2024-11-21 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in BogdanFix WP SendFox.This issue affects WP SendFox: from n/a through 1.3.0. | |||||
CVE-2024-27950 | 2024-11-21 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in sirv.Com Image Optimizer, Resizer and CDN – Sirv.This issue affects Image Optimizer, Resizer and CDN – Sirv: from n/a through 7.2.0. |