Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Ios Xr MEDIUM 5.5
CVE-2024-20343

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlyin…

Mitigation only
Fix from $1,600 2024-09-11
Autoupdate HIGH 7.8
CVE-2024-43492

Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

Fix: 4.72+
Fix from $1,950 2024-09-10
Power Automate HIGH 8.5
CVE-2024-43479

Microsoft Power Automate Desktop Remote Code Execution Vulnerability

Fix: 2.41.178.24249 / 2.42.331.24249+
Fix from $1,950 2024-09-10
Azure Stack Hub CRITICAL 9.0
CVE-2024-38220

Azure Stack Hub Elevation of Privilege Vulnerability

Fix: 1.2311.1.22+
Fix from $2,300 2024-09-10
Sql 2016 Azure Connect Feature Pack CRITICAL 9.8
CVE-2024-37341

Microsoft SQL Server Elevation of Privilege Vulnerability

Fix: 13.0.6441.1 / 13.0.7040.1+
Fix from $2,300 2024-09-10
Spectrum CRITICAL 9.8
CVE-2023-37234

Loftware Spectrum through 4.6 has unprotected JMX Registry.

Fix: after 4.6
Fix from $2,300 2024-09-10
Simatic Rf360r Firmware HIGH 7.5
CVE-2024-37993

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6B…

Fix: 1.1 / 2.2+
Fix from $1,950 2024-09-10
Insightiq MEDIUM 6.7
CVE-2024-39580

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access …

Fix: 5.1.1+
Fix from $1,600 2024-09-10
Connex Health Portal CRITICAL 9.1
CVE-2024-6796

In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated…

Fix: 2024-08-30+
Fix from $2,300 2024-09-09
One MEDIUM 6.5
CVE-2024-42021

An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

Fix: 12.2.0.4093+
Fix from $1,600 2024-09-07
One MEDIUM 5.3
CVE-2024-42022

An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.

Fix: 12.2.0.4093+
Fix from $1,600 2024-09-07
One HIGH 8.8
CVE-2024-42023

An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.

Fix: 12.2.0.4093+
Fix from $1,950 2024-09-07
Unclassified MEDIUM 5.3
CVE-2023-30582

A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used…

Mitigation only
Fix from $1,600 2024-09-07
Unclassified HIGH 7.5
CVE-2023-30583

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 2…

Mitigation only
Fix from $1,950 2024-09-07
Unclassified HIGH 7.5
CVE-2023-30587

A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspector module…

Mitigation only
Fix from $1,950 2024-09-07
C Mor Video Surveillance HIGH 8.1
CVE-2024-45170

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use admin…

No fix yet
Fix from $1,950 2024-09-04
Overleaf MEDIUM 5.4
CVE-2024-45313

Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-com…

Fix: 2024-07-17 / 2024-08-28+
Fix from $1,600 2024-09-02
Linen CRITICAL 9.8
CVE-2024-45522

Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages…

Fix: 2024-04-03+
Fix from $2,300 2024-09-02
Misp MEDIUM 6.5
CVE-2024-45509

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not…

Fix: 2.4.197+
Fix from $1,600 2024-09-01
Powermail CRITICAL 9.8
CVE-2024-45233

An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missi…

Fix: 7.5.0 / 8.5.0+
Fix from $2,300 2024-08-29
Exr MEDIUM 5.5
CVE-2024-44913

An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulne…

No fix yet
Fix from $1,600 2024-08-28
Exr MEDIUM 5.5
CVE-2024-44914

An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulne…

No fix yet
Fix from $1,600 2024-08-28
Exr MEDIUM 5.5
CVE-2024-44915

An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulne…

No fix yet
Fix from $1,600 2024-08-28
Life Insurance Management System MEDIUM 5.4
CVE-2024-8216

A vulnerability, which was classified as critical, has been found in nafisulbari/itsourcecode Insurance Management System 1.0. Affected by this issue…

Mitigation only
Fix from $1,600 2024-08-27
Wolfssl MEDIUM 5.3
CVE-2024-5814

A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful …

Fix: after 5.7.0
Fix from $1,600 2024-08-27
Cloud Data Management CRITICAL 9.8
CVE-2024-36068

An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to…

Fix: 8.1.3 / 9.0.3+
Fix from $2,300 2024-08-27
Beikeshop HIGH 8.8
CVE-2024-8164

A vulnerability was determined in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function rename of the file /Admin/Htt…

Fix: after 1.5.5
Fix from $1,950 2024-08-26
Bus Ticket Reservation System MEDIUM 5.4
CVE-2024-42766

Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.

Mitigation only
Fix from $1,600 2024-08-23
Sonicos CRITICAL 9.8
CVE-2024-40766 KEVEPSS 18%

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource…

Fix: 5.9.2.14-13o / 6.5.2.8-2n+
Fix from $2,300 2024-08-23
Entra Id HIGH 7.5
CVE-2024-43477

Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable …

Mitigation only
Fix from $1,950 2024-08-23