Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Micontact Center Business HIGH 8.1
CVE-2024-42514

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct a…

Fix: after 10.1.0.4
Fix from $1,950 2024-10-01
Elabftw MEDIUM 6.5
CVE-2024-45408

eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated u…

Fix: 5.1.0+
Fix from $1,600 2024-10-01
Unclassified HIGH 8.8
CVE-2024-46280

PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak credentials for a root-level a…

Mitigation only
Fix from $1,950 2024-09-30
Railway Reservation System MEDIUM 5.3
CVE-2024-9321

A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue affects some unknown process…

No fix yet
Fix from $1,600 2024-09-29
Testlink HIGH 8.1
CVE-2024-46097

TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental …

No fix yet
Fix from $1,950 2024-09-27
Unclassified HIGH 8.8
CVE-2024-45982

A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted pa…

Mitigation only
Fix from $1,950 2024-09-26
Unclassified CRITICAL 9.1
CVE-2024-46627

Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

Mitigation only
Fix from $2,300 2024-09-26
Solvait HIGH 7.5
CVE-2024-44860

An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted r…

No fix yet
Fix from $1,950 2024-09-26
Unclassified HIGH 8.4
CVE-2024-41605

In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse vi…

Mitigation only
Fix from $1,950 2024-09-26
Mattermost Server MEDIUM 5.4
CVE-2024-42406

Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived c…

Fix: 9.5.9 / 9.9.3+
Fix from $1,600 2024-09-26
iOS MEDIUM 5.8
CVE-2024-20465

A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series S…

Mitigation only
Fix from $1,600 2024-09-25
Icecms HIGH 7.6
CVE-2024-46607

Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password v…

Fix: after 3.4.7
Fix from $1,950 2024-09-25
Icecms HIGH 7.5
CVE-2024-46609

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and re…

Fix: after 3.4.7
Fix from $1,950 2024-09-25
Icecms HIGH 7.5
CVE-2024-46610

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a…

Fix: after 3.4.7
Fix from $1,950 2024-09-25
Music Management System CRITICAL 9.8
CVE-2024-42797

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnera…

No fix yet
Fix from $2,300 2024-09-25
Unclassified CRITICAL 9.8
CVE-2024-45489

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of …

Mitigation only
Fix from $2,300 2024-09-20
Jflow MEDIUM 5.3
CVE-2024-9003

A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadCo…

Mitigation only
Fix from $1,600 2024-09-19
365 Apps HIGH 7.8
CVE-2024-38016

Microsoft Office Visio Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-09-19
Directus MEDIUM 5.0
CVE-2024-46990

Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.…

Fix: 10.13.3 / 11.1.0+
Fix from $1,600 2024-09-18
Music Management System MEDIUM 5.9
CVE-2024-42796

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerabil…

No fix yet
Fix from $1,600 2024-09-16
Raid Web Console HIGH 7.8
CVE-2024-34543

Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of pr…

Mitigation only
Fix from $1,950 2024-09-16
Raid Web Console MEDIUM 5.7
CVE-2024-36247

Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable denial of service via adjacen…

Mitigation only
Fix from $1,600 2024-09-16
Raid Web Console MEDIUM 5.7
CVE-2024-36261

Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service vi…

Mitigation only
Fix from $1,600 2024-09-16
Raid Web Console MEDIUM 5.5
CVE-2024-28170

Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via lo…

Mitigation only
Fix from $1,600 2024-09-16
Raid Web Console MEDIUM 5.7
CVE-2024-32940

Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of servic…

Mitigation only
Fix from $1,600 2024-09-16
Unclassified HIGH 7.5
CVE-2023-43626

Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via l…

Mitigation only
Fix from $1,950 2024-09-16
Mattermost Desktop MEDIUM 5.3
CVE-2024-39772

Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality scre…

Fix: 5.9.0+
Fix from $1,600 2024-09-16
Omflow HIGH 8.8
CVE-2024-8779

OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regu…

Fix: 1.2.1.3+
Fix from $1,950 2024-09-16
Mstore Api MEDIUM 6.5
CVE-2024-8269

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions u…

Fix: 4.15.4+
Fix from $1,600 2024-09-13
Rely Pcie Firmware HIGH 8.8
CVE-2024-44571

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.

Fix: after 23.1.0
Fix from $1,950 2024-09-11