Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,672 CVEs tagged with CWE-862434 Critical, 1,954 High, 5,992 Medium, 291 Low, 1 Unrated.

CVE-2024-37317

Published Jun 14, 2024

The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37314

Published Jun 14, 2024

Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-51376

Published Jun 14, 2024

Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-5685

Published Jun 14, 2024

Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23504

Published Jun 14, 2024

Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.5.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51497

Published Jun 14, 2024

Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51496

Published Jun 14, 2024

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51495

Published Jun 14, 2024

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51377

Published Jun 14, 2024

Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-1094

Published Jun 14, 2024

The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to…

CVSS 7.3 · High

CVE-2023-51523

Published Jun 14, 2024

Missing Authorization vulnerability in WriterSystem WooCommerce Easy Duplicate Product.This issue affects WooCommerce Easy Duplicate Product: from n/a through 0.3.0.7.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-51516

Published Jun 14, 2024

Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51507

Published Jun 14, 2024

Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-36695

Published Jun 14, 2024

Missing Authorization vulnerability in Maxime Schoeni Sublanguage.This issue affects Sublanguage: from n/a through 2.9.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-36694

Published Jun 14, 2024

Missing Authorization vulnerability in Bryan Lee Kingkong Board.This issue affects Kingkong Board: from n/a through 2.1.0.2.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-36504

Published Jun 14, 2024

Missing Authorization vulnerability in BBS e-Theme BBS e-Popup.This issue affects BBS e-Popup: from n/a through 2.4.5.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-35045

Published Jun 14, 2024

Missing Authorization vulnerability in Fat Rat Fat Rat Collect.This issue affects Fat Rat Collect: from n/a through 2.6.7.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-35040

Published Jun 14, 2024

Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-29174

Published Jun 14, 2024

Missing Authorization vulnerability in NervyThemes SKU Label Changer For WooCommerce.This issue affects SKU Label Changer For WooCommerce: from n/a through 3.0.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-5674

Published Jun 12, 2024

The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the check_api_key function in all…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4898

Published Jun 12, 2024

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-51524

Published Jun 12, 2024

Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51413

Published Jun 12, 2024

Missing Authorization vulnerability in Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.29.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-48280

Published Jun 12, 2024

Missing Authorization vulnerability in Consensu.IO Consensu.Io.This issue affects Consensu.Io: from n/a through 1.0.1.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Showing 5,626-5,650 of 8,672 CVEsPage 226 of 347