Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-10-15 CVE-2024-38190 Missing Authorization vulnerability in Microsoft Power Platform
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
network
low complexity
microsoft CWE-862
8.6
2024-10-14 CVE-2024-45732 Missing Authorization vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a search as the "nobody" Splunk user in the SplunkDeploymentServerConfig app.
network
low complexity
splunk CWE-862
6.5
2024-10-12 CVE-2024-9756 Missing Authorization vulnerability in Directsoftware Order Attachments for Woocommerce
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1.
network
low complexity
directsoftware CWE-862
4.3
2024-10-12 CVE-2024-9187 The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteRm() function in all versions up to, and including, 1.1.8.
network
low complexity
CWE-862
4.3
2024-10-12 CVE-2024-9824 The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'ip_delete_post' and 'ip_update_post_title' functions in all versions up to, and including, 1.2.2.
network
low complexity
CWE-862
4.3
2024-10-12 CVE-2024-9860 The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3.
network
low complexity
CWE-862
6.5
2024-10-11 CVE-2024-9587 Missing Authorization vulnerability in Linkz.Ai
The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_linkz' function in versions up to, and including, 1.1.8.
network
low complexity
linkz-ai CWE-862
4.3
2024-10-10 CVE-2024-48902 Missing Authorization vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
network
low complexity
jetbrains CWE-862
5.4
2024-10-10 CVE-2024-9067 Missing Authorization vulnerability in Kainelabs Youzify
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all versions up to, and including, 1.3.0.
network
low complexity
kainelabs CWE-862
4.3
2024-10-10 CVE-2024-9520 Missing Authorization vulnerability in Wpuserplus Userplus 1.0/1.1/2.0
The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0.
network
low complexity
wpuserplus CWE-862
5.4