Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Mattermost Server MEDIUM 5.4
CVE-2024-39837

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary cha…

Fix: 9.5.7+
Fix from $1,600 2024-08-01
Mattermost MEDIUM 6.4
CVE-2024-36492

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing user…

Fix: 9.5.7 / 9.7.6+
Fix from $1,600 2024-08-01
Elfinder CRITICAL 9.8
CVE-2024-38909

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows a…

Mitigation only
Fix from $2,300 2024-07-30
Ipados HIGH 7.8
CVE-2024-40812

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.…

Fix: 1.3 / 10.6+
Fix from $1,950 2024-07-29
Ipados HIGH 7.5
CVE-2024-40786

This issue was addressed through improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Vent…

Fix: 13.6.8 / 16.7.9+
Fix from $1,950 2024-07-29
I Mcs Nfv CRITICAL 9.1
CVE-2024-28805

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

No fix yet
Fix from $2,300 2024-07-29
Unclassified MEDIUM 5.4
CVE-2024-6727

A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enable-scale-testing functionalit…

Mitigation only
Fix from $1,600 2024-07-29
A3700r Firmware HIGH 7.5
CVE-2024-7154

A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file…

No fix yet
Fix from $1,950 2024-07-28
Unclassified CRITICAL 9.8
CVE-2024-40117

Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting…

Mitigation only
Fix from $2,300 2024-07-26
Unclassified MEDIUM 5.3
CVE-2024-41806

The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the ins…

Patch available
Fix from $1,600 2024-07-25
Meshery CRITICAL 9.8
CVE-2024-36535

Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Mitigation only
Fix from $2,300 2024-07-24
Cert Manager HIGH 7.2
CVE-2024-36537

Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tok…

Mitigation only
Fix from $1,950 2024-07-24
Groupme HIGH 8.8
CVE-2024-38164

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to…

Patch available
Fix from $1,950 2024-07-23
Librechat CRITICAL 9.8
CVE-2024-41703

LibreChat through 0.7.4-rc1 has incorrect access control for message updates.

Fix: after 0.7.3
Fix from $2,300 2024-07-22
Lin Cms Spring Boot HIGH 7.5
CVE-2024-41600

Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login me…

Fix: after 0.2.1
Fix from $1,950 2024-07-19
Marketing MEDIUM 6.5
CVE-2024-21169

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Partners). Supported versions that are affected are 12.2.3-12.2…

Fix: after 12.2.13
Fix from $1,600 2024-07-16
Jd Edwards Enterpriseone Tools MEDIUM 6.1
CVE-2024-21150

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …

Fix: 9.2.8.2+
Fix from $1,600 2024-07-16
Process Manufacturing Product Development HIGH 8.1
CVE-2024-21153

Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The…

Mitigation only
Fix from $1,950 2024-07-16
Purchasing MEDIUM 5.4
CVE-2024-21132

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Approvals). Supported versions that are affected are 12.2.3-12…

Fix: after 12.2.13
Fix from $1,600 2024-07-16
Eg 2000se Firmware HIGH 7.5
CVE-2019-16640

An issue was found in upload.php on the Ruijie EG-2000 series gateway. A parameter passed to the class UploadFile is mishandled (%00 and /var/./html …

Mitigation only
Fix from $1,950 2024-07-16
Unclassified HIGH 7.3
CVE-2024-36438

eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card dupli…

Mitigation only
Fix from $1,950 2024-07-15
Electronic Official Document Management System HIGH 8.8
CVE-2024-6737

The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers…

Fix: 5.0.77+
Fix from $1,950 2024-07-15
Tronclass MEDIUM 5.3
CVE-2024-6738

The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific fil…

Fix: 1.69.61976+
Fix from $1,600 2024-07-15
Publiccms MEDIUM 6.5
CVE-2024-40547

PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace.

Fix: after 4.0.202302.e
Fix from $1,600 2024-07-12
GitLab CRITICAL 9.8
CVE-2024-6385EPSS 6%

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting …

Fix: 16.11.6 / 17.0.4+
Fix from $2,300 2024-07-11
Android HIGH 7.0
CVE-2024-34725

In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalat…

Mitigation only
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31320

In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM…

Patch available
Fix from $1,950 2024-07-09
Windows Server 2016 HIGH 7.8
CVE-2024-38100

Windows File Explorer Elevation of Privilege Vulnerability

Fix: 10.0.14393.7159 / 10.0.17763.6054+
Fix from $1,950 2024-07-09
Windows 10 1507 HIGH 7.5
CVE-2024-38061

DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability

Fix: 10.0.10240.20710 / 10.0.14393.7159+
Fix from $1,950 2024-07-09
Fortiextender Firmware HIGH 8.8
CVE-2024-23663

An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an at…

Fix: after 7.4.2
Fix from $1,950 2024-07-09