Search Results (9005 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-30534 1 Typps 1 Calendarista 2024-11-21 6.5 Medium
Missing Authorization vulnerability in typps Calendarista Basic Edition.This issue affects Calendarista Basic Edition: from n/a through 3.0.5.
CVE-2024-30529 1 Tainacan 1 Tainacan 2024-11-21 5.3 Medium
Missing Authorization vulnerability in Tainacan.Org Tainacan.This issue affects Tainacan: from n/a through 0.20.7.
CVE-2024-30528 1 Spiffyplugins 1 Spiffy Calendar 2024-11-21 5.4 Medium
Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.
CVE-2024-30525 1 Moveaddons 1 Move Addons For Elementor 2024-11-21 5.3 Medium
Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9.
CVE-2024-30517 1 Slicedinvoices 1 Sliced Invoices 2024-11-21 4.3 Medium
Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2.
CVE-2024-30515 1 Pixelite 1 Events Manager 2024-11-21 4.3 Medium
Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.
CVE-2024-30512 1 Weformspro 1 Weforms 2024-11-21 3.7 Low
Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20.
CVE-2024-30485 1 Xlplugins 1 Finale 2024-11-21 8.8 High
Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.
CVE-2024-30484 1 Risethemes 1 Rt Easy Builder 2024-11-21 4.3 Medium
Missing Authorization vulnerability in RT Easy Builder – Advanced addons for Elementor.This issue affects RT Easy Builder – Advanced addons for Elementor: from n/a through 2.0.
CVE-2024-30470 1 Yithemes 1 Woocommerce Account Funds 2024-11-21 6.5 Medium
Missing Authorization vulnerability in YITH YITH WooCommerce Account Funds Premium.This issue affects YITH WooCommerce Account Funds Premium: from n/a through 1.33.0.
CVE-2024-30467 1 Wpdeveloper 1 Essential Blocks 2024-11-21 6.5 Medium
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg.This issue affects Essential Blocks for Gutenberg: from n/a through 4.4.9.
CVE-2024-30466 1 Onthegosystems 1 Woocommerce Multilingual \& Multicurrency 2024-11-21 5.4 Medium
Missing Authorization vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.4.
CVE-2024-30465 1 Pagelayer 1 Pagelayer 2024-11-21 6.5 Medium
Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1.
CVE-2024-30464 1 Wpzoom 1 Social Icons Widget 2024-11-21 5.4 Medium
Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.
CVE-2024-30459 2024-11-21 5.3 Medium
Missing Authorization vulnerability in AIpost AI WP Writer.This issue affects AI WP Writer: from n/a through 3.6.5.
CVE-2024-30217 2024-11-21 4.3 Medium
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting the integrity of the application. Confidentiality and Availability are not impacted.
CVE-2024-30216 2024-11-21 4.3 Medium
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of the application. Confidentiality and Availability are not impacted.
CVE-2024-2882 2024-11-21 N/A
SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. This breach could potentially lead to unauthorized control, data manipulation, and access to sensitive information within the SCADA system.
CVE-2024-2743 1 Gitlab 1 Gitlab 2024-11-21 5.3 Medium
An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.
CVE-2024-2544 1 Sygnoos 1 Popup Builder 2024-11-21 7.4 High
The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple unauthorized actions, such as deleting subscribers, and importing subscribers to conduct stored cross-site scripting attacks.