Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Free Exam Hall Seating Management System CRITICAL 9.8
CVE-2024-10766

A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some u…

No fix yet
Fix from $2,300 2024-11-04
Online Institute Management System CRITICAL 9.8
CVE-2024-10764

A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /p…

No fix yet
Fix from $2,300 2024-11-04
Online Institute Management System CRITICAL 9.8
CVE-2024-10765

A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of…

No fix yet
Fix from $2,300 2024-11-04
Unclassified MEDIUM 5.4
CVE-2024-7424

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capab…

Mitigation only
Fix from $1,600 2024-11-01
Aspnetcore.utilities.cloudstorage MEDIUM 5.3
CVE-2024-50353

ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of th…

Fix: 8.0.0+
Fix from $1,600 2024-10-30
Unclassified HIGH 8.1
CVE-2024-48955

Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return o…

Mitigation only
Fix from $1,950 2024-10-29
Data Lakehouse MEDIUM 6.5
CVE-2024-47481

Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent netwo…

Mitigation only
Fix from $1,600 2024-10-25
Online Exam System HIGH 7.2
CVE-2024-10353

A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /admin-da…

No fix yet
Fix from $1,950 2024-10-25
Zimaos MEDIUM 5.3
CVE-2024-48932

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http://<Ser…

Fix: 1.2.5+
Fix from $1,600 2024-10-24
Unclassified MEDIUM 6.9
CVE-2024-9692

VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attacker can issue an unauthorized …

Mitigation only
Fix from $1,600 2024-10-24
Antivirus One HIGH 7.8
CVE-2024-45334

Trend Micro Antivirus One versions 3.10.4 and below (Consumer) is vulnerable to an Arbitrary Configuration Update that could allow unauthorized acces…

Fix: 3.10.6+
Fix from $1,950 2024-10-22
Umbraco Cms MEDIUM 6.5
CVE-2024-48925

Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version …

Fix: 14.3.0+
Fix from $1,600 2024-10-22
Unclassified HIGH 7.4
CVE-2020-36838

The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function…

Mitigation only
Fix from $1,950 2024-10-16
Social Networks Auto Poster MEDIUM 6.5
CVE-2020-36831

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple …

Fix: 4.3.18+
Fix from $1,600 2024-10-16
Azure Functions MEDIUM 6.5
CVE-2024-38204

Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.

Patch available
Fix from $1,600 2024-10-15
Vm Virtualbox MEDIUM 5.3
CVE-2024-21248

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: after 7.1.2
Fix from $1,600 2024-10-15
Bi Publisher HIGH 7.6
CVE-2024-21195

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0…

Mitigation only
Fix from $1,950 2024-10-15
H2o HIGH 7.5
CVE-2024-45397

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-R…

Fix: 2024-10-10+
Fix from $1,950 2024-10-11
Commerce MEDIUM 5.3
CVE-2024-45124

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could resul…

Mitigation only
Fix from $1,600 2024-10-10
Commerce MEDIUM 6.5
CVE-2024-45118

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could resul…

Mitigation only
Fix from $1,600 2024-10-10
Unclassified HIGH 8.2
CVE-2024-46539

Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of…

Mitigation only
Fix from $1,950 2024-10-08
Visual C\+\+ Redistributable HIGH 7.8
CVE-2024-43590

Visual C++ Redistributable Installer Elevation of Privilege Vulnerability

Fix: 14.40.33816 / 15.9.67+
Fix from $1,950 2024-10-08
Sharepoint Server HIGH 7.8
CVE-2024-43503

Microsoft SharePoint Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2024-10-08
Windows Server 2008 HIGH 7.4
CVE-2024-43456

Windows Remote Desktop Services Tampering Vulnerability

Fix: 10.0.14393.7428 / 10.0.17763.6414+
Fix from $1,950 2024-10-08
Unclassified MEDIUM 6.7
CVE-2024-47976

Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access.

Mitigation only
Fix from $1,600 2024-10-07
Unclassified HIGH 7.0
CVE-2024-47975

Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or…

Mitigation only
Fix from $1,950 2024-10-07
Workbooth HIGH 7.8
CVE-2024-9576

Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script.

No fix yet
Fix from $1,950 2024-10-07
Unclassified HIGH 7.2
CVE-2024-47910

An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an ex…

Mitigation only
Fix from $1,950 2024-10-04
Taskcafe CRITICAL 9.8
CVE-2023-26770

TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.

No fix yet
Fix from $2,300 2024-10-04
Bandiview MEDIUM 6.5
CVE-2024-45870

Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.

No fix yet
Fix from $1,600 2024-10-03