Total
5241 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-55994 | 2024-12-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in 搜狐畅言 畅言评论系统 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 畅言评论系统: from n/a through 2.0.5. | |||||
CVE-2024-55993 | 2024-12-16 | N/A | 5.3 MEDIUM | ||
Missing Authorization vulnerability in PickPlugins Job Board Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through 2.1.60. | |||||
CVE-2024-55992 | 2024-12-16 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Basic Ordernumbers: from n/a through 1.4.4. | |||||
CVE-2024-54417 | 2024-12-16 | N/A | 5.3 MEDIUM | ||
Missing Authorization vulnerability in Pixelgrade PixProof allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PixProof: from n/a through 2.0.1. | |||||
CVE-2024-54402 | 2024-12-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in Jozoor Arabic Webfonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arabic Webfonts: from n/a through 1.4.6. | |||||
CVE-2024-54384 | 2024-12-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in eLightUp Falcon – WordPress Optimizations & Tweaks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Falcon – WordPress Optimizations & Tweaks: from n/a through 2.8.3. | |||||
CVE-2024-54379 | 2024-12-16 | N/A | 8.8 HIGH | ||
Missing Authorization vulnerability in Blokhaus Minterpress allows Privilege Escalation.This issue affects Minterpress: from n/a through 1.0.5. | |||||
CVE-2024-54378 | 2024-12-16 | N/A | 8.8 HIGH | ||
Missing Authorization vulnerability in Quietly Quietly Insights allows Privilege Escalation.This issue affects Quietly Insights: from n/a through 1.2.2. | |||||
CVE-2024-54369 | 2024-12-16 | N/A | 9.1 CRITICAL | ||
Missing Authorization vulnerability in ThemeHunk Zita Site Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through 1.0.2. | |||||
CVE-2024-54359 | 2024-12-16 | N/A | 8.2 HIGH | ||
Missing Authorization vulnerability in Saul Morales Pacheco Banner System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Banner System: from n/a through 1.0.0. | |||||
CVE-2024-54354 | 2024-12-16 | N/A | 6.5 MEDIUM | ||
Missing Authorization vulnerability in Beat Kueffer Termin-Kalender allows Stored XSS.This issue affects Termin-Kalender: from n/a through 0.99.47. | |||||
CVE-2024-28230 | 1 Jetbrains | 1 Youtrack | 2024-12-16 | N/A | 6.5 MEDIUM |
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions | |||||
CVE-2023-40105 | 1 Google | 1 Android | 2024-12-13 | N/A | 5.5 MEDIUM |
In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2023-40113 | 1 Google | 1 Android | 2024-12-13 | N/A | 5.5 MEDIUM |
In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2024-5318 | 1 Gitlab | 1 Gitlab | 2024-12-13 | N/A | 4.0 MEDIUM |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts. | |||||
CVE-2024-54326 | 2024-12-13 | N/A | 6.5 MEDIUM | ||
Missing Authorization vulnerability in Eyal Fitoussi GEO my WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GEO my WordPress: from n/a through 4.5.0.4. | |||||
CVE-2024-54323 | 2024-12-13 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in WPExpertsio New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through 2.6.2. | |||||
CVE-2024-54311 | 2024-12-13 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in i.lychkov Mark New Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mark New Posts: from n/a through 7.5.1. | |||||
CVE-2024-54310 | 2024-12-13 | N/A | 5.3 MEDIUM | ||
Missing Authorization vulnerability in Aslam Khan Gouran Gou Manage My Account Menu allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Gou Manage My Account Menu: from n/a through 1.0.1.8. | |||||
CVE-2024-54298 | 2024-12-13 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in Bill Minozzi Car Dealer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Dealer: from n/a through 4.46. |