Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attacker…
CVSS 8.2
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers c…
CVSS 6.5
Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions.
CVSS 7.3
Unauthenticated Broken Access Control in The7 <= 14.2.2 versions.
CVSS 7.5
Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions.
CVSS 8.8
Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions.
CVSS 7.5
Missing Authorization vulnerability in Awesomemotive Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from …
CVSS 7.5
Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
CVSS 6.5
Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.
CVSS 7.5
Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
CVSS 6.5
Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.
CVSS 7.5
Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.
CVSS 7.5