Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-05-17 CVE-2023-51479 Missing Authorization vulnerability in Buildapp Build APP Online
Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.
network
low complexity
buildapp CWE-862
8.8
2024-05-16 CVE-2024-4222 Missing Authorization vulnerability in Themeum Tutor LMS
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0.
network
low complexity
themeum CWE-862
8.2
2024-05-14 CVE-2024-4317 Missing Authorization vulnerability in Postgresql
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users.
network
low complexity
postgresql CWE-862
4.3
2024-05-14 CVE-2024-4444 Missing Authorization vulnerability in Thimpress Learnpress
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5.
network
low complexity
thimpress CWE-862
6.5
2024-05-14 CVE-2024-32712 Missing Authorization vulnerability in Podlove Podcast Publisher
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.
network
low complexity
podlove CWE-862
4.3
2024-05-07 CVE-2021-35001 Missing Authorization vulnerability in BMC Track-It!
BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability.
network
low complexity
bmc CWE-862
6.5
2024-05-07 CVE-2024-23704 Missing Authorization vulnerability in Google Android 13.0/14.0
In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check.
local
low complexity
google CWE-862
7.8
2024-05-03 CVE-2024-33914 Missing Authorization vulnerability in Exclusiveaddons Exclusive Addons for Elementor
Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.
network
low complexity
exclusiveaddons CWE-862
critical
9.8
2024-05-02 CVE-2024-2043 Missing Authorization vulnerability in Theinnovs Eleforms
The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when downloading form submissions in all versions up to, and including, 2.9.9.7.
network
low complexity
theinnovs CWE-862
5.3
2024-05-02 CVE-2024-3942 Missing Authorization vulnerability in Stylemixthemes Masterstudy LMS
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8.
network
low complexity
stylemixthemes CWE-862
5.4