Vulnerabilities (CVE)

Filtered by CWE-862
Total 9945 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-47361 1 Webtechstreet 1 Elementor Addon Elements 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This issue affects Elementor Addon Elements: from n/a through <= 1.13.6.
CVE-2024-47358 1 Code-atlantic 1 Popup Maker 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n/a through <= 1.19.2.
CVE-2024-47337 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: from n/a through <= 2.3.1.
CVE-2024-47330 1 Supsystic 2 Slider, Social Share Buttons 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons by Supsystic: from n/a through 2.2.9.
CVE-2024-47321 1 Androidbubbles 1 Wp Datepicker 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in Fahad Mahmood WP Datepicker wp-datepicker.This issue affects WP Datepicker: from n/a through <= 2.1.1.
CVE-2024-47318 1 Magazine3 1 Pwa For Wp \& Amp 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Magazine3 PWA for WP & AMP pwa-for-wp.This issue affects PWA for WP & AMP: from n/a through <= 1.7.72.
CVE-2024-47317 1 Wpquads 1 Ads 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded.This issue affects Ads by WPQuads: from n/a through <= 2.0.84.
CVE-2024-47314 1 Sunshinephotocart 1 Sunshine Photo Cart 2026-06-17 N/A 7.1 HIGH
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.8.
CVE-2024-47311 1 Kraftplugins 1 Wheel Of Life 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through <= 1.1.8.
CVE-2024-47308 1 Templately 1 Templately 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in WPDeveloper Templately templately.This issue affects Templately: from n/a through <= 3.1.2.
CVE-2024-47302 1 Wpmanageninja 1 Fluent Support 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through <= 1.8.0.
CVE-2024-47268 1 Synology 2 Diskstation Manager, Surveillance Station 2026-06-17 N/A 4.9 MEDIUM
Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.
CVE-2024-47055 1 Acquia 1 Mautic 2026-06-17 N/A 4.3 MEDIUM
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR) / Missing Authorization: A missing authorization vulnerability exists in the cloneAction of the segment management. This allows an authenticated user to bypass intended permission restrictions and clone segments even if they lack the necessary permissions to create new ones. MitigationUpdate Mautic to a version that implements proper authorization checks for the cloneAction within the ListController.php. Ensure that users attempting to clone segments possess the appropriate creation permissions.
CVE-2024-46450 1 Tenda 2 Ac6, Ac6 Firmware 2026-06-17 N/A 8.1 HIGH
Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.
CVE-2024-45760 1 Dell 1 Openmanage Server Administrator 2026-06-17 N/A 4.3 MEDIUM
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.
CVE-2024-45732 1 Splunk 2 Splunk, Splunk Cloud Platform 2026-06-17 N/A 7.1 HIGH
In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a search as the "nobody" Splunk user in the SplunkDeploymentServerConfig app. This could let the low-privileged user access potentially restricted data.
CVE-2024-45689 1 Moodle 1 Moodle 2026-06-17 N/A 6.5 MEDIUM
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
CVE-2024-45591 1 Xwiki 1 Xwiki 2026-06-17 N/A 5.3 MEDIUM
XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the version number, the author of the modification (both username and displayed name) and the version comment. This information is exposed regardless of the rights setup, and even when the wiki is configured to be fully private. On a private wiki, this can be tested by accessing /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history, if this shows the history of the main page then the installation is vulnerable. This has been patched in XWiki 15.10.9 and XWiki 16.3.0RC1.
CVE-2024-45493 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate with an internal user account from the network (if they know their password).
CVE-2024-45461 1 Apache 1 Cloudstack 2026-06-17 N/A 5.7 MEDIUM
The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments where the feature is enabled, due to missing access check enforcements, non-administrative CloudStack user accounts are able to access and modify quota-related configurations and data. This issue affects Apache CloudStack from 4.7.0 through 4.18.2.3; and from 4.19.0.0 through 4.19.1.1, where the Quota feature is enabled. Users are recommended to upgrade to Apache CloudStack 4.18.2.4 or 4.19.1.2, or later, which addresses this issue. Alternatively, users that do not use the Quota feature are advised to disabled the plugin by setting the global setting "quota.enable.service" to "false".