Vulnerabilities (CVE)

Filtered by CWE-862
Total 4833 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-45760 1 Gvectors 1 Wpdiscuz 2025-05-29 N/A 4.3 MEDIUM
Missing Authorization vulnerability in gVectors Team wpDiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through 7.6.3.
CVE-2024-32715 1 Olivethemes 1 Olive One Click Demo Import 2025-05-29 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
CVE-2023-46309 1 Gvectors 1 Wpdiscuz 2025-05-29 N/A 5.3 MEDIUM
Missing Authorization vulnerability in gVectors Team wpDiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through 7.6.10.
CVE-2022-41238 1 Jenkins 1 Dotci 2025-05-29 N/A 9.8 CRITICAL
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.
CVE-2024-32792 1 Incsub 1 Hummingbird 2025-05-29 N/A 4.3 MEDIUM
Missing Authorization vulnerability in WPMU DEV Hummingbird.This issue affects Hummingbird: from n/a through 3.7.3.
CVE-2024-8437 1 Plugingarden 1 Wp Easy Gallery 2025-05-29 N/A 4.3 MEDIUM
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and wpeg_add_gallery in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify galleries.
CVE-2023-42706 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42698 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 N/A 5.5 MEDIUM
In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42685 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42681 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 N/A 7.8 HIGH
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2024-47055 2025-05-29 N/A 4.3 MEDIUM
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the cloneAction of the segment management. This allows an authenticated user to bypass intended permission restrictions and clone segments even if they lack the necessary permissions to create new ones. MitigationUpdate Mautic to a version that implements proper authorization checks for the cloneAction within the ListController.php. Ensure that users attempting to clone segments possess the appropriate creation permissions.
CVE-2023-42747 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 N/A 7.8 HIGH
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42736 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 N/A 7.8 HIGH
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2024-31099 1 Averta 1 Shortcodes And Extra Features For Phlox Theme 2025-05-29 N/A 6.4 MEDIUM
Missing Authorization vulnerability in Averta Shortcodes and extra features for Phlox theme auxin-elements.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.7.
CVE-2024-37444 1 Wpmudev 1 Defender 2025-05-28 N/A 5.3 MEDIUM
Missing Authorization vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.7.1.
CVE-2024-39635 1 Kainelabs 1 Youzify 2025-05-28 N/A 5.4 MEDIUM
Missing Authorization vulnerability in KaineLabs Youzify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youzify: from n/a through 1.2.6.
CVE-2024-12113 1 Kainelabs 1 Youzify 2025-05-28 N/A 4.3 MEDIUM
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_user_review() and delete_review() functions in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete other user's reviews.
CVE-2025-1813 1 Zframeworks 1 Zz 2025-05-28 5.0 MEDIUM 4.3 MEDIUM
A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-43158 1 Masteriyo 1 Masteriyo 2025-05-28 N/A 7.5 HIGH
Missing Authorization vulnerability in Masteriyo Masteriyo - LMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masteriyo - LMS: from n/a through 1.11.4.
CVE-2024-43159 1 Masteriyo 1 Masteriyo 2025-05-28 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Masteriyo Masteriyo - LMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masteriyo - LMS: from n/a through 1.11.6.