Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-10-02 CVE-2024-20477 Missing Authorization vulnerability in Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller
A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files on an affected device. This vulnerability exists because of missing authorization controls on the affected REST API endpoint.
network
low complexity
cisco CWE-862
5.4
2024-10-01 CVE-2024-8430 The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in all versions up to, and including, 1.2.5.
network
low complexity
CWE-862
5.3
2024-10-01 CVE-2024-8548 The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in all versions up to, and including, 1.6.6.
network
low complexity
CWE-862
8.1
2024-10-01 CVE-2024-8632 The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6.
network
low complexity
CWE-862
6.5
2024-10-01 CVE-2024-8675 The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions up to, and including, 2.1.2.
network
low complexity
CWE-862
4.3
2024-09-28 CVE-2024-9297 Missing Authorization vulnerability in Oretnom23 Railway Reservation System 1.0
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0.
network
low complexity
oretnom23 CWE-862
6.3
2024-09-28 CVE-2024-9189 Missing Authorization vulnerability in Wpfactory Eu/Uk VAT Manager for Woocommerce
The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12.
network
low complexity
wpfactory CWE-862
5.3
2024-09-26 CVE-2024-8771 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34.
network
low complexity
CWE-862
4.3
2024-09-26 CVE-2024-9025 Missing Authorization vulnerability in Codesupply Sight
The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title' function in all versions up to, and including, 1.1.2.
network
low complexity
codesupply CWE-862
5.3
2024-09-26 CVE-2024-47330 Missing Authorization vulnerability in Supsystic Slider and Social Share Buttons
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons by Supsystic: from n/a through 2.2.9.
network
low complexity
supsystic CWE-862
8.8