Total
9936 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-4434 | 1 Hamza417 | 1 Inure | 2026-06-17 | N/A | 6.1 MEDIUM |
| Missing Authorization in GitHub repository hamza417/inure prior to build88. | |||||
| CVE-2023-4374 | 1 Froger | 1 Wp Remote Users Sync | 2026-06-17 | N/A | 4.3 MEDIUM |
| The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to view logs. | |||||
| CVE-2023-4302 | 1 Jenkins | 1 Fortify | 2026-06-17 | N/A | 4.2 MEDIUM |
| A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |||||
| CVE-2023-4282 | 1 Wpdeveloper | 1 Embedpress | 2026-06-17 | N/A | 5.4 MEDIUM |
| The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2. This makes it possible for authenticated attackers with subscriber privileges or above, to delete plugin settings. | |||||
| CVE-2023-4245 | 1 Rednao | 1 Woocommerce Pdf Invoice Builder | 2026-06-17 | N/A | 4.3 MEDIUM |
| The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided they can guess the order id and invoice id. | |||||
| CVE-2023-4198 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 6.5 MEDIUM |
| Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data | |||||
| CVE-2023-4164 | 1 Google | 2 Android, Pixel | 2026-06-17 | N/A | 8.4 HIGH |
| There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional execution privileges needed. | |||||
| CVE-2023-4124 | 1 Answer | 1 Answer | 2026-06-17 | N/A | 6.5 MEDIUM |
| Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1. | |||||
| CVE-2023-4106 | 1 Mattermost | 1 Mattermost | 2026-06-17 | N/A | 6.3 MEDIUM |
| Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks. | |||||
| CVE-2023-4105 | 1 Mattermost | 1 Mattermost | 2026-06-17 | N/A | 3.1 LOW |
| Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message | |||||
| CVE-2023-4104 | 1 Mozilla | 1 Vpn | 2026-06-17 | N/A | 5.5 MEDIUM |
| An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN 2.16.1 < (Linux). | |||||
| CVE-2023-4059 | 1 Cozmoslabs | 1 Profile Builder | 2026-06-17 | N/A | 4.3 MEDIUM |
| The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog | |||||
| CVE-2023-4027 | 1 Softlabbd | 1 Radio Player | 2026-06-17 | N/A | 5.3 MEDIUM |
| The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update plugin settings. | |||||
| CVE-2023-4025 | 1 Softlabbd | 1 Radio Player | 2026-06-17 | N/A | 5.3 MEDIUM |
| The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update player instances. | |||||
| CVE-2023-4024 | 1 Softlabbd | 1 Radio Player | 2026-06-17 | N/A | 5.3 MEDIUM |
| The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to delete player instances. | |||||
| CVE-2023-49981 | 1 Oretnom23 | 1 School Fees Management System | 2026-06-17 | N/A | 7.5 HIGH |
| A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization. | |||||
| CVE-2023-49980 | 1 Mayurik | 1 Best Student Result Management System | 2026-06-17 | N/A | 7.5 HIGH |
| A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization. | |||||
| CVE-2023-49979 | 1 Mayurik | 1 Best Student Management System | 2026-06-17 | N/A | 7.5 HIGH |
| A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization. | |||||
| CVE-2023-49861 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in socialmediafeather Social Media Feather social-media-feather allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media Feather: from n/a through <= 2.1.3. | |||||
| CVE-2023-49859 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in Marcus (aka @msykes) Login With Ajax login-with-ajax allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login With Ajax: from n/a through <= 4.1. | |||||
