Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-01-16 CVE-2024-0235 Missing Authorization vulnerability in Myeventon Eventon
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
network
low complexity
myeventon CWE-862
5.3
2024-01-16 CVE-2024-0236 Missing Authorization vulnerability in Myeventon Eventon
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
network
low complexity
myeventon CWE-862
5.3
2024-01-16 CVE-2024-0237 Missing Authorization vulnerability in Myeventon Eventon
The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc
network
low complexity
myeventon CWE-862
5.3
2024-01-16 CVE-2024-0238 Missing Authorization vulnerability in Myeventon Eventon
The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.
network
low complexity
myeventon CWE-862
6.1
2024-01-16 CVE-2024-0570 Missing Authorization vulnerability in Totolink N350Rt Firmware 9.3.5U.6265
A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265.
network
low complexity
totolink CWE-862
critical
9.1
2024-01-16 CVE-2024-0569 Missing Authorization vulnerability in Totolink T8 Firmware 4.1.5Cu.83320220905
A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905.
network
low complexity
totolink CWE-862
critical
9.1
2024-01-16 CVE-2023-34063 Missing Authorization vulnerability in VMWare Aria Automation and Cloud Foundation
Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.
network
low complexity
vmware CWE-862
8.3
2024-01-15 CVE-2023-5905 Missing Authorization vulnerability in Demomentsomtres Export Posts With Images
The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected posts.
network
low complexity
demomentsomtres CWE-862
8.1
2024-01-15 CVE-2023-6029 Missing Authorization vulnerability in Spider-Themes Eazydocs
The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.
network
low complexity
spider-themes CWE-862
7.5
2024-01-15 CVE-2023-6048 Missing Authorization vulnerability in Estatik
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of the site's options to 1, which could be used to break sites and lead to DoS when certain options are reset
network
low complexity
estatik CWE-862
6.5