Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Computer Laboratory Management System MEDIUM 6.5
CVE-2024-41332

Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers …

No fix yet
Fix from $1,600 2024-08-12
Online Exam System CRITICAL 9.8
CVE-2024-40480

A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remo…

Mitigation only
Fix from $2,300 2024-08-12
Best House Rental Management System HIGH 8.8
CVE-2024-40475

SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_rep…

Mitigation only
Fix from $1,950 2024-08-12
Var1200 H Firmware HIGH 8.6
CVE-2024-29082

Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and p…

Fix: after 3.3.23.6.9
Fix from $1,950 2024-08-12
Onyx HIGH 8.8
CVE-2024-0104

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access.…

Fix: 3.10.4402 / 3.11.2002+
Fix from $1,950 2024-08-08
Shopware MEDIUM 5.9
CVE-2024-42354

Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be mark…

Fix: 6.5.8.13 / 6.6.5.1+
Fix from $1,600 2024-08-08
Emui HIGH 7.1
CVE-2024-42033

Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confi…

No fix yet
Fix from $1,950 2024-08-08
Windows 10 1607 HIGH 7.3
CVE-2024-38202

Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic use…

Patch available
Fix from $1,950 2024-08-08
Windows 10 1507 MEDIUM 6.7
CVE-2024-21302

Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtu…

Fix: 10.0.10240.20710 / 10.0.14393.7259+
Fix from $1,600 2024-08-08
Poly Clariti Manager CRITICAL 9.8
CVE-2024-41912

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement …

Fix: 10.12.0.2_100+
Fix from $2,300 2024-08-07
Responsive School Management System MEDIUM 5.3
CVE-2024-41243

An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows rem…

No fix yet
Fix from $1,600 2024-08-07
Responsive School Management System MEDIUM 5.3
CVE-2024-41244

An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows rem…

No fix yet
Fix from $1,600 2024-08-07
Responsive School Management System MEDIUM 5.3
CVE-2024-41245

An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows …

No fix yet
Fix from $1,600 2024-08-07
Responsive School Management System MEDIUM 5.3
CVE-2024-41250

An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows …

No fix yet
Fix from $1,600 2024-08-07
Enjay Crm HIGH 7.8
CVE-2024-41309

An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-l…

No fix yet
Fix from $1,950 2024-08-07
Responsive School Management System MEDIUM 5.3
CVE-2024-41246

An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allow…

No fix yet
Fix from $1,600 2024-08-07
Responsive School Management System MEDIUM 5.3
CVE-2024-41247

An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management S…

No fix yet
Fix from $1,600 2024-08-07
Responsive School Management System MEDIUM 5.3
CVE-2024-41248

An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Manageme…

No fix yet
Fix from $1,600 2024-08-07
Responsive School Management System MEDIUM 5.3
CVE-2024-41249

An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows r…

No fix yet
Fix from $1,600 2024-08-07
Responsive School Management System MEDIUM 6.5
CVE-2024-41251

An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php…

No fix yet
Fix from $1,600 2024-08-07
Responsive School Management System MEDIUM 6.5
CVE-2024-41252

An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php…

No fix yet
Fix from $1,600 2024-08-07
Enjay Crm HIGH 7.8
CVE-2024-41308

An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level pri…

No fix yet
Fix from $1,950 2024-08-07
MongoDB HIGH 7.8
CVE-2024-7553

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Win…

Fix: 1.18.1 / 1.26.2+
Fix from $1,950 2024-08-07
Firefox HIGH 8.1
CVE-2024-7525

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of r…

Fix: 115.14.0 / 129.0+
Fix from $1,950 2024-08-06
Unclassified HIGH 8.8
CVE-2024-40531

A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute…

Mitigation only
Fix from $1,950 2024-08-05
315 5g Iot Modem Firmware HIGH 7.8
CVE-2024-33027

Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.

Patch available
Fix from $1,950 2024-08-05
Feripro HIGH 7.5
CVE-2024-41518

An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allows remote attackers to export …

Fix: after 2.2.3
Fix from $1,950 2024-08-02
Mattermost Server HIGH 7.1
CVE-2024-41144

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are e…

Fix: 9.5.7 / 9.7.6+
Fix from $1,950 2024-08-01
Mattermost MEDIUM 6.5
CVE-2024-39274

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the …

Fix: 9.5.7 / 9.7.6+
Fix from $1,600 2024-08-01
Mattermost CRITICAL 9.6
CVE-2024-39777

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local …

Fix: 9.5.7 / 9.7.6+
Fix from $2,300 2024-08-01