Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Hotel Management System HIGH 7.5
CVE-2024-42772

An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated at…

No fix yet
Fix from $1,950 2024-08-22
Hotel Management System CRITICAL 9.1
CVE-2024-42775

An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unau…

No fix yet
Fix from $2,300 2024-08-22
Hotel Management System HIGH 7.2
CVE-2024-42776

Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.

No fix yet
Fix from $1,950 2024-08-22
Unclassified MEDIUM 5.4
CVE-2024-36441

Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are rece…

Mitigation only
Fix from $1,600 2024-08-22
Unclassified HIGH 7.6
CVE-2024-36443

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.

Mitigation only
Fix from $1,950 2024-08-22
Mattermost HIGH 7.2
CVE-2024-8071

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system adm…

Fix: 9.5.8 / 9.8.3+
Fix from $1,950 2024-08-22
Azure Managed Instance For Apache Cassandra HIGH 8.8
CVE-2024-38175

An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges ov…

Mitigation only
Fix from $1,950 2024-08-20
Escan Management Console CRITICAL 9.8
CVE-2024-42919

eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

No fix yet
Fix from $2,300 2024-08-20
Joomla\! HIGH 7.5
CVE-2024-27187

Improper Access Controls allows backend users to overwrite their username when disallowed.

Fix: 4.4.7 / 5.1.3+
Fix from $1,950 2024-08-20
Ghost MEDIUM 6.5
CVE-2024-43409

Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform me…

Fix: 5.89.5+
Fix from $1,600 2024-08-20
Unclassified CRITICAL 9.8
CVE-2024-42559

An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a val…

Mitigation only
Fix from $2,300 2024-08-20
Jielink\+ Jsotc2016 CRITICAL 9.8
CVE-2024-7921

A vulnerability has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805 and classified as problematic. Affect…

Fix: after 20240805
Fix from $2,300 2024-08-19
Jielink\+ Jsotc2016 CRITICAL 9.8
CVE-2024-7919

A vulnerability, which was classified as critical, has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. T…

Fix: after 20240805
Fix from $2,300 2024-08-19
Jielink\+ Jsotc2016 CRITICAL 9.8
CVE-2024-7920

A vulnerability, which was classified as problematic, was found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. Aff…

Fix: after 20240805
Fix from $2,300 2024-08-19
Flask Cors HIGH 7.5
CVE-2024-6221

A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. T…

Patch available
Fix from $1,950 2024-08-18
Lr350 Firmware CRITICAL 9.8
CVE-2024-42967

Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the usernam…

No fix yet
Fix from $2,300 2024-08-15
Arc A Graphics MEDIUM 5.5
CVE-2024-28050

Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to poten…

Fix: 31.0.101.4824+
Fix from $1,600 2024-08-14
Agilex 7 Fpga Firmware HIGH 7.9
CVE-2024-25576

improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege…

Fix: 24.1+
Fix from $1,950 2024-08-14
Aptio V Uefi Firmware Integrator Tools HIGH 7.8
CVE-2024-26022

Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable esca…

Fix: 5.05.04.0008 / 5.13.00.2106+
Fix from $1,950 2024-08-14
Ethernet 800 Series Controllers Driver HIGH 8.8
CVE-2024-24986

Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an auth…

Fix: 28.3+
Fix from $1,950 2024-08-14
Computing Improvement Program MEDIUM 5.5
CVE-2023-43489

Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of servi…

Fix: 2.4.10717+
Fix from $1,600 2024-08-14
Windows 10 21h2 HIGH 7.8
CVE-2024-38163

Windows Update Stack Elevation of Privilege Vulnerability

Fix: 10.0.19041.3920 / 10.0.20348.2201+
Fix from $1,950 2024-08-14
Windows 10 1507 MEDIUM 6.8
CVE-2024-38223

Windows Initial Machine Configuration Elevation of Privilege Vulnerability

Fix: 10.0.10240.20751 / 10.0.14393.7259+
Fix from $1,600 2024-08-13
Azure Cyclecloud HIGH 7.8
CVE-2024-38195

Azure CycleCloud Remote Code Execution Vulnerability

Fix: 8.6.3+
Fix from $1,950 2024-08-13
Azure Connected Machine Agent HIGH 7.8
CVE-2024-38162

Azure Connected Machine Agent Elevation of Privilege Vulnerability

Fix: 1.44+
Fix from $1,950 2024-08-13
Uprof MEDIUM 5.5
CVE-2023-31341

Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds w…

Fix: 4.1.424 / 4.2.816+
Fix from $1,600 2024-08-13
Fortios MEDIUM 5.5
CVE-2024-36505

An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an …

Fix: 7.0.15 / 7.2.8+
Fix from $1,600 2024-08-13
Sinec Traffic Analyzer MEDIUM 6.5
CVE-2024-41905

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access…

Fix: 2.0+
Fix from $1,600 2024-08-13
Netweaver Application Server Abap MEDIUM 5.4
CVE-2024-41732

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on t…

Mitigation only
Fix from $1,600 2024-08-13
Kamaji CRITICAL 9.9
CVE-2024-42480

Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC f…

Patch available
Fix from $2,300 2024-08-12