The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,346 vulnerabilities with CWE-862
CVE-2024-13370
MEDIUM
Youzify - BuddyPress Community <1.3.2 - Privilege Escalation
CVSS 6.5
CVE-2024-13368
MEDIUM
Youzify - BuddyPress <1.3.2 - Privilege Escalation
CVSS 4.3
CVE-2024-12826
MEDIUM
GoHero Store Customizer - Info Disclosure
CVSS 4.3
CVE-2024-12113
MEDIUM
Youzify < 1.3.3 - Authenticated Unauthorized Data Deletion via Review Deletion Functions
CVSS 4.3
CVE-2024-13698
MEDIUM
Jobify WordPress Theme <= 4.2.7 - Unauthenticated Arbitrary File Upload
CVSS 6.5
CVE-2024-13335
MEDIUM
Spexo Addons for Elementor - Auth Bypass
CVSS 4.3
CVE-2024-13447
MEDIUM
WP Hotel Booking <2.1.6 - Info Disclosure
CVSS 4.3
CVE-2024-13361
MEDIUM
WordPress AI Power: Complete AI Pack <1.8.96 - Auth Bypass
CVSS 6.3
CVE-2024-12879
MEDIUM
QuantumCloud WPBot Pro Wordpress Chatbot <= 13.5.5 - Authenticated Data Modification via Missing Capability Check
CVSS 4.3
CVE-2024-12104
MEDIUM
Atarim < 4.1.0 - Unauthenticated Data Deletion via Missing Capability Check
CVSS 5.3
CVE-2024-12071
MEDIUM
Evergreen Content Poster < 1.4.4 - Unauthenticated Arbitrary Post Deletion via delete_network_post Function
CVSS 5.3
CVE-2024-50967
MEDIUM
Becon DATAGerry <2.2.0 - Info Disclosure
CVSS 6.5
CVE-2024-12370
MEDIUM
WP Hotel Booking <= 2.1.5 - Unauthenticated Room Addition via Missing Capability Check
CVSS 5.3
CVE-2024-13367
MEDIUM
Sandbox plugin <0.4 - Info Disclosure
CVSS 6.5
CVE-2024-46450
HIGH
Tenda AC6 v2.0 Firmware v15.03.06.50 - Missing Authorization
CVSS 8.1
CVE-2024-57682
MEDIUM
D-Link DIR-816 Firmware 816A2_FWv1.10CNB05_R1B011D88210 - Unauthenticated Information Disclosure via d_status.asp
CVSS 6.5
CVE-2024-12614
HIGH
Passwords Manager <= 1.4.8 - Authenticated Unauthorized Data Modification via AJAX Actions
CVSS 7.5
CVE-2024-12427
MEDIUM
Multi Step Form <= 1.7.23 - Unauthenticated Limited File Upload via fw_upload_file AJAX Action
CVSS 5.3
CVE-2024-57726
CRITICAL
KEV
SimpleHelp < 5.5.8 - Missing Authorization for API Key Creation
CVSS 9.9
CVE-2024-54470
MEDIUM
iPadOS < 17.7.1 and < 18.1 - Unauthenticated Contacts Access from Lock Screen
CVSS 4.6
CVE-2024-40839
LOW
iPadOS < 17.5 - Unauthenticated Notification Content Exposure from Lock Screen
CVSS 2.4
CVE-2024-56295
MEDIUM
Ays Pro Poll Maker <= 5.5.6 - Missing Authorization
CVSS 6.5
CVE-2024-11851
MEDIUM
NitroPack <1.17.0 - Privilege Escalation
CVSS 4.3
CVE-2024-11848
HIGH
NitroPack <1.17.0 - Info Disclosure
CVSS 8.1
CVE-2024-57757
HIGH
jeewms < 2025.01.01 - Missing Authorization in AuthInterceptor
CVSS 7.5
Details
Vulnerabilities
8,346
Exploit Likelihood
High