Total
4661 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-13312 | 2025-01-31 | N/A | 5.3 MEDIUM | ||
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 12.4.0 before 12.4.9. | |||||
CVE-2024-54155 | 1 Jetbrains | 1 Youtrack | 2025-01-31 | N/A | 3.7 LOW |
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | |||||
CVE-2024-54153 | 1 Jetbrains | 1 Youtrack | 2025-01-31 | N/A | 3.1 LOW |
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | |||||
CVE-2022-45351 | 1 Muffingroup | 1 Betheme | 2025-01-31 | N/A | 5.4 MEDIUM |
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. | |||||
CVE-2022-45352 | 1 Muffingroup | 1 Betheme | 2025-01-31 | N/A | 5.4 MEDIUM |
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. | |||||
CVE-2022-45356 | 1 Muffingroup | 1 Betheme | 2025-01-31 | N/A | 5.4 MEDIUM |
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. | |||||
CVE-2023-39998 | 1 Muffingroup | 1 Betheme | 2025-01-31 | N/A | 8.2 HIGH |
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1. | |||||
CVE-2022-45349 | 1 Muffingroup | 1 Betheme | 2025-01-31 | N/A | 4.3 MEDIUM |
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. | |||||
CVE-2024-1380 | 1 Relevanssi | 1 Relevanssi | 2025-01-31 | N/A | 5.3 MEDIUM |
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0. This makes it possible for unauthenticated attackers to export the query log data. The vendor has indicated that they may look into adding a capability check for proper authorization control, however, this vulnerability is theoretically patched as is. | |||||
CVE-2025-22720 | 2025-01-31 | N/A | 5.8 MEDIUM | ||
Missing Authorization vulnerability in MagePeople Team Booking and Rental Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Booking and Rental Manager: from n/a through 2.2.1. | |||||
CVE-2025-22265 | 2025-01-31 | N/A | 6.5 MEDIUM | ||
Missing Authorization vulnerability in mgplugin EMI Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EMI Calculator: from n/a through 1.1. | |||||
CVE-2024-13530 | 2025-01-31 | N/A | 4.3 MEDIUM | ||
The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the lps_handle_delete_all_logs(), lps_handle_delete_login_log(), and lps_handle_end_session() functions in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete login logs and end user sessions. | |||||
CVE-2024-13717 | 2025-01-31 | N/A | 4.3 MEDIUM | ||
The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to enabled and disable widgets. | |||||
CVE-2024-13424 | 2025-01-31 | N/A | 4.3 MEDIUM | ||
The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'niwoosc_ajax' AJAX endpoint in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins settings and modify commission amounts. | |||||
CVE-2024-13415 | 2025-01-31 | N/A | 4.3 MEDIUM | ||
The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's settings. | |||||
CVE-2024-13767 | 2025-01-31 | N/A | 8.1 HIGH | ||
The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). | |||||
CVE-2024-1991 | 1 Metagauss | 1 Registrationmagic | 2025-01-31 | N/A | 8.8 HIGH |
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_users_role() function in all versions up to, and including, 5.3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an administrator | |||||
CVE-2025-24461 | 1 Jetbrains | 1 Teamcity | 2025-01-30 | N/A | 6.5 MEDIUM |
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint | |||||
CVE-2024-13715 | 1 Ikjweb | 1 Zstore Manager Basic | 2025-01-30 | N/A | 4.3 MEDIUM |
The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the zstore_clear_cache() function in all versions up to, and including, 3.311. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's cache. | |||||
CVE-2024-37204 | 1 Wp-property-hive | 1 Propertyhive | 2025-01-29 | N/A | 4.3 MEDIUM |
Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9. |