Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

9,119 CVEs tagged with CWE-862479 Critical, 2,091 High, 6,248 Medium, 300 Low, 1 Unrated.

CVE-2024-12028

Published Dec 6, 2024

The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1.…

CVSS 5.3 · Medium

CVE-2024-12027

Published Dec 6, 2024

The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateFilter() and deleteFil…

CVSS 4.3 · Medium

CVE-2024-11323

Published Dec 6, 2024

The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ai_…

CVSS 8.8 · High

CVE-2024-54679

Published Dec 5, 2024

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11643

Published Dec 4, 2024

The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check…

CVSS 8.8 · High

CVE-2024-54155

Published Dec 4, 2024

In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-54153

Published Dec 4, 2024

In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-10567

Published Dec 4, 2024

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up t…

CVSS 7.5 · High

CVE-2024-10664

Published Dec 4, 2024

The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ba…

CVSS 4.3 · Medium

CVE-2024-10663

Published Dec 4, 2024

The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the goodbye_form_call…

CVSS 4.3 · Medium

CVE-2024-42453

Published Dec 4, 2024

A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11844

Published Dec 3, 2024

The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53938

Published Dec 2, 2024

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default and exposed over the LAN. T…

CVSS 8.8 · High

CVE-2024-49581

Published Dec 2, 2024

Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such…

CVSS 6.5 · Medium

CVE-2024-53784

Published Dec 2, 2024

Missing Authorization vulnerability in E-goi Smart Marketing SMS and Newsletters Forms smart-marketing-for-wp allows Exploiting Incorrectly Configured Access Control Security Leve…

CVSS 4.3 · Medium

CVE-2024-53708

Published Dec 2, 2024

Missing Authorization vulnerability in kekotron AI Quiz ai-quiz allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AI Quiz: from n/a through <= 1.1.

CVSS 5.3 · Medium

CVE-2024-53605

Published Dec 2, 2024

Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.

CVSS 7.5 · High

CVE-2024-11918

Published Nov 28, 2024

The Image Alt Text plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the iat_add_alt_txt_action and iat_update_alt_txt_…

CVSS 4.3 · Medium

CVE-2017-13316

Published Nov 27, 2024

In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10580

Published Nov 27, 2024

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on the submit_f…

CVSS 5.3 · Medium

CVE-2024-8114

Published Nov 26, 2024

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10579

Published Nov 26, 2024

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the preview_mo…

CVSS 4.3 · Medium

CVE-2024-10542

Published Nov 26, 2024

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse D…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-49596

Published Nov 26, 2024

Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,401-5,425 of 9,119 CVEsPage 217 of 365