Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,673 CVEs tagged with CWE-862434 Critical, 1,954 High, 5,993 Medium, 291 Low, 1 Unrated.

CVE-2023-4025

Published Aug 17, 2024

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and inc…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4024

Published Aug 17, 2024

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and inc…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6500

Published Aug 17, 2024

The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_req…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2024-38699

Published Aug 13, 2024

Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for…

CVSS 7.5 · High

CVE-2024-37935

Published Aug 13, 2024

Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woocommerce OpenPos: from n/a…

CVSS 7.5 · High

CVE-2024-42373

Published Aug 13, 2024

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exp…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41734

Published Aug 13, 2024

Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to discl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39591

Published Aug 13, 2024

SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42377

Published Aug 13, 2024

SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42376

Published Aug 13, 2024

SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attack…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37930

Published Aug 12, 2024

Insertion of Sensitive Information into Log File vulnerability in ThemeSphere SmartMag smartmag-responsive-retina-wordpress-magazine.This issue affects SmartMag: from n/a through…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7648

Published Aug 12, 2024

The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payment…

CVSS 4.3 · Medium

CVE-2024-7621

Published Aug 12, 2024

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check…

CVSS 5.4 · Medium

CVE-2024-6760

Published Aug 12, 2024

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42470

Published Aug 12, 2024

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Several endpoints in versions prior to 4.2.1 of the CometVis…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42035

Published Aug 8, 2024

Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6824

Published Aug 8, 2024

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'check_temp_validity' an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6987

Published Aug 8, 2024

The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'orchid_store_activate_plugin' function in all ver…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6869

Published Aug 8, 2024

The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43045

Published Aug 7, 2024

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access other users'…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,451-5,475 of 8,673 CVEsPage 219 of 347