Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,672 CVEs tagged with CWE-862434 Critical, 1,954 High, 5,992 Medium, 291 Low, 1 Unrated.

CVE-2024-7031

Published Aug 3, 2024

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5331

Published Aug 1, 2024

The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6698

Published Aug 1, 2024

The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta u…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41108

Published Jul 31, 2024

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only the host's mac address is requ…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37901

Published Jul 31, 2024

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code exe…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-37898

Published Jul 31, 2024

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7135

Published Jul 31, 2024

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2508

Published Jul 31, 2024

The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_menu_item_icon function in all versions up…

CVSS 5.3 · Medium

CVE-2024-40834

Published Jul 29, 2024

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41624

Published Jul 29, 2024

Incorrect access control in Himalaya Xiaoya nano smart speaker rom_version 1.6.96 allows a remote attacker to have an unspecified impact.

CVSS 6.3 · Medium

CVE-2024-6458

Published Jul 27, 2024

The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on the wcpt_presets__duplicate_pres…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6591

Published Jul 27, 2024

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_ca…

CVSS 5.8 · Medium

CVE-2024-4410

Published Jul 27, 2024

The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability check…

CVSS 5.4 · Medium

CVE-2024-1804

Published Jul 27, 2024

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml function in a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1798

Published Jul 27, 2024

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_export_xml function in all versi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6836

Published Jul 24, 2024

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is vulnerable to u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5861

Published Jul 24, 2024

The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() func…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6755

Published Jul 24, 2024

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_mult…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6754

Published Jul 24, 2024

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ functio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6750

Published Jul 24, 2024

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all ver…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6806

Published Jul 22, 2024

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affec…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6805

Published Jul 22, 2024

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result in information disclosure or re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6636

Published Jul 20, 2024

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6491

Published Jul 20, 2024

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,476-5,500 of 8,672 CVEsPage 220 of 347