Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Fortiadc MEDIUM 6.5
CVE-2023-50181

An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticate…

Fix: 7.2.5 / 7.4.2+
Fix from $1,600 2024-07-09
Unclassified HIGH 8.6
CVE-2024-39697

phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due …

Patch available
Fix from $1,950 2024-07-09
Directus HIGH 7.7
CVE-2024-39701

Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators.…

Fix: 10.6.0+
Fix from $1,950 2024-07-08
Http File Server HIGH 8.8
CVE-2024-39943EPSS 39%

rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have…

Fix: 0.52.10+
Fix from $1,950 2024-07-04
Unclassified HIGH 7.8
CVE-2024-39934

Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shar…

Patch available
Fix from $1,950 2024-07-04
Mattermost MEDIUM 6.5
CVE-2024-6428

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows…

Fix: 9.5.6 / 9.6.3+
Fix from $1,600 2024-07-03
Mattermost MEDIUM 5.3
CVE-2024-36257

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server…

Fix: 9.5.6+
Fix from $1,600 2024-07-03
Mattermost MEDIUM 5.4
CVE-2024-39361

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which a…

Fix: 9.5.6 / 9.6.3+
Fix from $1,600 2024-07-03
Authentik HIGH 8.8
CVE-2024-37905

authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to g…

Fix: 2024.2.4 / 2024.4.3+
Fix from $1,950 2024-06-28
Authentik CRITICAL 9.8
CVE-2024-38371

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow…

Fix: 2024.2.4 / 2024.4.3+
Fix from $2,300 2024-06-28
Markoni D \(compact\) Firmware CRITICAL 9.8
CVE-2024-39376

TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their design…

Fix: 2.0.1+
Fix from $2,300 2024-06-27
GitLab HIGH 8.8
CVE-2024-5655EPSS 7%

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting …

Fix: 16.11.5 / 17.0.3+
Fix from $1,950 2024-06-27
GitLab MEDIUM 5.3
CVE-2024-2191

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting …

Fix: 16.11.5 / 17.0.3+
Fix from $1,600 2024-06-27
Unclassified HIGH 8.2
CVE-2024-37742

Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB k…

Mitigation only
Fix from $1,950 2024-06-25
Unclassified HIGH 7.4
CVE-2024-21740

Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.

No fix yet
Fix from $1,950 2024-06-25
Unclassified CRITICAL 9.8
CVE-2024-21741

GigaDevice GD32E103C8T6 devices have Incorrect Access Control.

No fix yet
Fix from $2,300 2024-06-25
Unclassified CRITICAL 9.8
CVE-2024-33898

Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows r…

Mitigation only
Fix from $2,300 2024-06-24
Access Management Specialist HIGH 7.5
CVE-2024-37677

An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacker to obtain sensitive informa…

No fix yet
Fix from $1,950 2024-06-24
Unclassified MEDIUM 5.3
CVE-2024-38873

An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails t…

Mitigation only
Fix from $1,600 2024-06-21
Unclassified MEDIUM 6.5
CVE-2022-41324

Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to so…

Mitigation only
Fix from $1,600 2024-06-20
Unclassified HIGH 8.8
CVE-2022-45929

Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their rol…

Mitigation only
Fix from $1,950 2024-06-20
Moodle MEDIUM 5.4
CVE-2024-38273

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

Fix: 4.1.11 / 4.2.8+
Fix from $1,600 2024-06-18
Unclassified HIGH 8.2
CVE-2022-23829

A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Manage…

Mitigation only
Fix from $1,950 2024-06-18
Unclassified HIGH 8.5
CVE-2024-5650

DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to int…

Mitigation only
Fix from $1,950 2024-06-17
Nextcloud Server MEDIUM 5.4
CVE-2024-37884

Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got sh…

Fix: 25.0.13.7 / 26.0.13+
Fix from $1,600 2024-06-14
Nextcloud Server HIGH 8.1
CVE-2024-37882

Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissi…

Fix: 23.0.12.17 / 24.0.12.13+
Fix from $1,950 2024-06-14
User Oidc MEDIUM 6.3
CVE-2024-37312

user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account…

Fix: 5.0.0+
Fix from $1,600 2024-06-14
Secure Connect Gateway MEDIUM 5.4
CVE-2024-28965

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabl…

Fix: after 5.22.00.18
Fix from $1,600 2024-06-13
Secure Connect Gateway MEDIUM 5.4
CVE-2024-28966

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabl…

Fix: after 5.22.00.18
Fix from $1,600 2024-06-13
Secure Connect Gateway MEDIUM 5.4
CVE-2024-28967

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if …

Fix: after 5.22.00.18
Fix from $1,600 2024-06-13