Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-37204 Missing Authorization vulnerability in Wp-Property-Hive Propertyhive
Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.
network
low complexity
wp-property-hive CWE-862
4.3
2024-11-01 CVE-2024-37277 Unspecified vulnerability in Strangerstudios Paid Memberships PRO
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
network
low complexity
strangerstudios
critical
9.8
2024-11-01 CVE-2024-37453 Missing Authorization vulnerability in Metagauss Profilegrid
Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 5.8.7.
network
low complexity
metagauss CWE-862
8.8
2024-11-01 CVE-2024-37463 Unspecified vulnerability in Crmperks CRM Perks Forms
Missing Authorization vulnerability in CRM Perks CRM Perks Forms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CRM Perks Forms: from n/a through 1.1.5.
network
low complexity
crmperks
critical
9.8
2024-11-01 CVE-2024-37517 Missing Authorization vulnerability in Brainstormforce Spectra
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.13.7.
network
low complexity
brainstormforce CWE-862
8.8
2024-11-01 CVE-2024-43162 Missing Authorization vulnerability in Awesomemotive Easy Digital Downloads
Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.2.12.
network
low complexity
awesomemotive CWE-862
8.8
2024-11-01 CVE-2024-43253 Unspecified vulnerability in Zaytech Smart Online Order for Clover
Missing Authorization vulnerability in Zaytech Smart Online Order for Clover allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Smart Online Order for Clover: from n/a through 1.5.6.
network
low complexity
zaytech
critical
9.8
2024-11-01 CVE-2024-43254 Missing Authorization vulnerability in Zaytech Smart Online Order for Clover
Missing Authorization vulnerability in Zaytech Smart Online Order for Clover allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Online Order for Clover: from n/a through 1.5.6.
network
low complexity
zaytech CWE-862
8.8
2024-11-01 CVE-2024-43293 Missing Authorization vulnerability in Wpzoom Recipe Card Blocks for Gutenberg & Elementor
Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Recipe Card Blocks for Gutenberg & Elementor: from n/a through 3.3.1.
network
low complexity
wpzoom CWE-862
8.8
2024-11-01 CVE-2024-43296 Missing Authorization vulnerability in Bplugins Html5 Video Player
Missing Authorization vulnerability in bPlugins LLC Flash & HTML5 Video allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flash & HTML5 Video: from n/a through 2.5.30.
network
low complexity
bplugins CWE-862
8.8