Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Secure Connect Gateway MEDIUM 5.4
CVE-2024-28968

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection setting…

Fix: after 5.22.00.18
Fix from $1,600 2024-06-13
Coldfusion HIGH 7.5
CVE-2024-34112EPSS 24%

ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system r…

Mitigation only
Fix from $1,950 2024-06-13
Commerce CRITICAL 9.8
CVE-2024-34107

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in…

Fix: after 1.4.0
Fix from $2,300 2024-06-13
Experience Manager CRITICAL 9.8
CVE-2024-26029

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature…

Fix: 6.5.21 / 2024.5+
Fix from $2,300 2024-06-13
Chrome MEDIUM 6.5
CVE-2024-5840

Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML pag…

Fix: 126.0.6478.54+
Fix from $1,600 2024-06-11
Visual Studio 2017 MEDIUM 6.7
CVE-2024-29060

Visual Studio Elevation of Privilege Vulnerability

Fix: 15.9.63 / 16.11.37+
Fix from $1,600 2024-06-11
Firefox MEDIUM 5.3
CVE-2024-5687

If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. …

Fix: 127.0+
Fix from $1,600 2024-06-11
Apex One HIGH 7.8
CVE-2024-37289

An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Pl…

Fix: 14.0.0.12980 / 14.0.13139+
Fix from $1,950 2024-06-10
Ipados HIGH 8.8
CVE-2024-27855

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, macOS…

Fix: 13.6.7 / 14.5+
Fix from $1,950 2024-06-10
macOS MEDIUM 5.5
CVE-2024-27792

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user…

Fix: 14.4+
Fix from $1,600 2024-06-10
macOS HIGH 7.8
CVE-2022-48683

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13. An app may be able to break out of its s…

Fix: 13.0+
Fix from $1,950 2024-06-10
Authlib HIGH 7.5
CVE-2024-37568

lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verific…

Fix: 1.3.1+
Fix from $1,950 2024-06-09
Jch Optimize HIGH 8.8
CVE-2024-30481

Broken Access Control vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.0.0.

Fix: 4.0.1+
Fix from $1,950 2024-06-09
Dynamsoft Service CRITICAL 9.8
CVE-2024-22074

Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.12…

Fix: 1.3.3212 / 1.4.3212+
Fix from $2,300 2024-06-06
Kanboard MEDIUM 6.3
CVE-2024-36399

Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php functio…

Fix: 1.2.37+
Fix from $1,600 2024-06-06
Buddypress Members Only MEDIUM 5.3
CVE-2024-0972

The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the …

Fix: after 3.3.5
Fix from $1,600 2024-06-06
The Moneytizer HIGH 8.1
CVE-2023-6966

The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capabil…

Fix: 10.0.1+
Fix from $1,950 2024-06-06
The Moneytizer MEDIUM 5.4
CVE-2023-6968

The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.6.3. This is due to missi…

Fix: 10.0.1+
Fix from $1,600 2024-06-06
Exynos 980 Firmware HIGH 7.5
CVE-2024-28818

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exy…

Mitigation only
Fix from $1,950 2024-06-05
Unclassified HIGH 7.5
CVE-2024-2019

The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to lack of a def…

Mitigation only
Fix from $1,950 2024-06-04
Fastconnect 6700 Firmware HIGH 7.8
CVE-2024-23360

Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.

No fix yet
Fix from $1,950 2024-06-03
Zkbio Cvsecurity HIGH 8.1
CVE-2024-35433

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create…

No fix yet
Fix from $1,950 2024-05-30
Unclassified MEDIUM 5.3
CVE-2024-0434

The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due t…

Mitigation only
Fix from $1,600 2024-05-29
Pe6208 Firmware MEDIUM 5.3
CVE-2023-43847

Incorrect access control in the outlet control function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to cont…

Fix: 2.4.239+
Fix from $1,600 2024-05-28
Pe6208 Firmware HIGH 8.0
CVE-2023-43848

Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to…

Fix: 2.4.239+
Fix from $1,950 2024-05-28
Pe6208 Firmware MEDIUM 6.5
CVE-2023-43849

Incorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to submit…

Fix: 2.4.239+
Fix from $1,600 2024-05-28
P3 550e Firmware CRITICAL 9.1
CVE-2024-22187

A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.…

No fix yet
Fix from $2,300 2024-05-28
P3 550e Firmware HIGH 7.5
CVE-2024-23315

A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550E 1.2.10.9…

No fix yet
Fix from $1,950 2024-05-28
Curiem Wfg9b Firmware HIGH 7.8
CVE-2023-52711

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place …

Mitigation only
Fix from $1,950 2024-05-28
Curiem Wfg9b Firmware HIGH 7.8
CVE-2023-52712

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place …

Mitigation only
Fix from $1,950 2024-05-28