Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Best Employee Management System HIGH 7.2
CVE-2024-11214

A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown c…

No fix yet
Fix from $1,950 2024-11-14
Eyoucms HIGH 7.2
CVE-2024-11211

A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. …

Fix: after 1.6.7
Fix from $1,950 2024-11-14
Server Board M70klp2sb Firmware MEDIUM 6.7
CVE-2024-39609

Improper Access Control in UEFI firmware for some Intel(R) Server Board M70KLP may allow a privileged user to potentially enable escalation of privil…

Fix: 01.04.0030+
Fix from $1,600 2024-11-13
Unclassified MEDIUM 5.3
CVE-2024-39285

Improper access control in UEFI firmware in some Intel(R) Server M20NTP Family may allow a privileged user to potentially enable information disclosu…

Mitigation only
Fix from $1,600 2024-11-13
Driver \& Support Assistant HIGH 7.8
CVE-2024-36488

Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege v…

Fix: 24.3.26.8+
Fix from $1,950 2024-11-13
Unclassified MEDIUM 6.7
CVE-2024-34022

Improper Access Control in some Thunderbolt(TM) Share software before version 1.0.49.9 may allow an authenticated user to potentially enable escalati…

Mitigation only
Fix from $1,600 2024-11-13
Endpoint Management Assistant HIGH 8.2
CVE-2024-32483

Improper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of pr…

Fix: 1.13.1.0+
Fix from $1,950 2024-11-13
Unclassified MEDIUM 6.8
CVE-2024-32044

Improper access control for some Intel(R) Arc(TM) Pro Graphics for Windows drivers before version 31.0.101.5319 may allow an authenticated user to po…

Mitigation only
Fix from $1,600 2024-11-13
Unclassified MEDIUM 5.5
CVE-2024-29085

Improper access control for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticated user to potentially enable esc…

Mitigation only
Fix from $1,600 2024-11-13
Unclassified MEDIUM 6.7
CVE-2024-29077

Improper access control in some JAM STAPL Player software before version 2.6.1 may allow an authenticated user to potentially enable escalation of pr…

Mitigation only
Fix from $1,600 2024-11-13
Remote Ssh HIGH 7.1
CVE-2024-49049

Visual Studio Code Remote Extension Elevation of Privilege Vulnerability

Fix: 0.115.1+
Fix from $1,950 2024-11-12
Visual Studio 2022 MEDIUM 6.7
CVE-2024-49044

Visual Studio Elevation of Privilege Vulnerability

Fix: 17.6.21 / 17.8.16+
Fix from $1,600 2024-11-12
Windows 10 21h2 HIGH 7.8
CVE-2024-43530

Windows Update Stack Elevation of Privilege Vulnerability

Fix: 10.0.19044.5131 / 10.0.19045.5131+
Fix from $1,950 2024-11-12
Dedecms CRITICAL 9.8
CVE-2024-11138

A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_a…

Mitigation only
Fix from $2,300 2024-11-12
Aptio V HIGH 7.1
CVE-2024-2315

APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability ma…

Fix: 5.037+
Fix from $1,950 2024-11-12
Lingdang Crm CRITICAL 9.8
CVE-2024-11122

A vulnerability, which was classified as critical, has been found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this issue is s…

Fix: after 8.6.4.3
Fix from $2,300 2024-11-12
Simple Music Cloud Community System CRITICAL 9.8
CVE-2024-11054

A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code o…

No fix yet
Fix from $2,300 2024-11-10
Real Estate Management System HIGH 7.2
CVE-2024-11000

A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown func…

No fix yet
Fix from $1,950 2024-11-08
Real Estate Management System HIGH 7.2
CVE-2024-10999

A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file …

No fix yet
Fix from $1,950 2024-11-08
Online Institute Management System HIGH 8.8
CVE-2024-10993

A vulnerability, which was classified as critical, was found in Codezips Online Institute Management System 1.0. Affected is an unknown function of t…

No fix yet
Fix from $1,950 2024-11-08
Online Institute Management System HIGH 8.8
CVE-2024-10994

A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected by this vulnerability is an un…

No fix yet
Fix from $1,950 2024-11-08
Data Domain Operating System HIGH 7.2
CVE-2024-48010

Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileg…

Fix: 7.7.5.50 / 7.10.1.40+
Fix from $1,950 2024-11-08
Unclassified MEDIUM 5.3
CVE-2019-20462

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this seria…

Mitigation only
Fix from $1,600 2024-11-07
Itop HIGH 7.1
CVE-2024-51995

Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allo…

Fix: 3.2.0+
Fix from $1,950 2024-11-07
Neuron MEDIUM 6.5
CVE-2024-10965

A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the fi…

Fix: after 2.10.0
Fix from $1,600 2024-11-07
Unclassified MEDIUM 6.5
CVE-2024-51988

RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the…

Mitigation only
Fix from $1,600 2024-11-06
Dns 320 Firmware MEDIUM 5.3
CVE-2024-10916

A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown p…

No fix yet
Fix from $1,600 2024-11-06
Waybox Pro Firmware HIGH 8.8
CVE-2023-29121

Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,950 2024-11-05
Waybox Pro Firmware MEDIUM 6.5
CVE-2023-29115

In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,600 2024-11-05
Unclassified HIGH 8.7
CVE-2024-51734

Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by…

Mitigation only
Fix from $1,950 2024-11-04