Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Mattermost Server MEDIUM 5.9
CVE-2024-32045

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linki…

Fix: 8.1.13 / 9.5.4+
Fix from $1,600 2024-05-26
Mattermost Server MEDIUM 6.3
CVE-2024-31859

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a pl…

Fix: 8.1.13 / 9.5.4+
Fix from $1,600 2024-05-26
Cp900l Firmware CRITICAL 9.8
CVE-2024-35396

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attac…

Mitigation only
Fix from $2,300 2024-05-24
Unclassified MEDIUM 5.9
CVE-2024-35222

Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications can access the Tauri IPC endp…

Mitigation only
Fix from $1,600 2024-05-23
Unclassified CRITICAL 9.8
CVE-2024-5168

Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthent…

Mitigation only
Fix from $2,300 2024-05-23
Opencti HIGH 8.1
CVE-2024-26139

OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack of certain…

Fix: after 5.12.31
Fix from $1,950 2024-05-23
Endpoint Manager Mobile MEDIUM 6.7
CVE-2024-22026

A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitra…

Fix: 12.1.0.0+
Fix from $1,600 2024-05-22
I HIGH 7.8
CVE-2024-27264

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Mitigation only
Fix from $1,950 2024-05-22
Secure Firewall Threat Defense MEDIUM 5.8
CVE-2024-20261

A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could all…

Mitigation only
Fix from $1,600 2024-05-22
Unclassified HIGH 8.8
CVE-2024-33227

An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execute arbitrary code via sending …

Mitigation only
Fix from $1,950 2024-05-22
Wpbot MEDIUM 5.0
CVE-2024-0451

The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback f…

Fix: 5.3.6+
Fix from $1,600 2024-05-22
Wpbot HIGH 7.7
CVE-2024-0452

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_ca…

Fix: 5.3.6+
Fix from $1,950 2024-05-22
Wpbot HIGH 7.7
CVE-2024-0453

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_ca…

Fix: 5.3.6+
Fix from $1,950 2024-05-22
Linux Kernel HIGH 8.8
CVE-2023-52801

In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In iopt_…

Fix: 6.5.13 / 6.6.3+
Fix from $1,950 2024-05-21
Unclassified HIGH 7.5
CVE-2024-4988

The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to the risk of private file leakag…

Mitigation only
Fix from $1,950 2024-05-21
Unclassified CRITICAL 9.8
CVE-2024-36080

Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-…

Mitigation only
Fix from $2,300 2024-05-19
Unclassified MEDIUM 6.7
CVE-2024-21828

Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to pot…

Mitigation only
Fix from $1,600 2024-05-16
Unclassified MEDIUM 5.5
CVE-2023-47859

Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially…

Mitigation only
Fix from $1,600 2024-05-16
Graphics Performance Analyzers Framework HIGH 7.8
CVE-2023-43748

Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enabl…

Fix: 2023.3+
Fix from $1,950 2024-05-16
Power Gadget HIGH 7.8
CVE-2023-45217

Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation o…

Fix: 3.6.0+
Fix from $1,950 2024-05-16
Power Gadget HIGH 8.8
CVE-2023-40070

Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalatio…

Mitigation only
Fix from $1,950 2024-05-16
Graphics Performance Analyzers HIGH 7.8
CVE-2023-40071

Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalati…

Fix: 2023.3+
Fix from $1,950 2024-05-16
Ethernet Controller I225 It Firmware HIGH 7.8
CVE-2022-37341

Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user t…

Fix: 1.87 / 29.0.1+
Fix from $1,950 2024-05-16
Unclassified HIGH 7.0
CVE-2022-37410

Improper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user to potentially enable escalat…

Mitigation only
Fix from $1,950 2024-05-16
Mlflow MEDIUM 5.4
CVE-2024-4263

A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an expe…

Fix: 2.12.1+
Fix from $1,600 2024-05-16
Unclassified MEDIUM 6.5
CVE-2024-28087

In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription …

Mitigation only
Fix from $1,600 2024-05-15
Acrobat Dc HIGH 7.8
CVE-2024-34099

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrar…

Fix: 20.005.30635 / 20.005.30636+
Fix from $1,950 2024-05-15
Intune Mobile Application Management MEDIUM 5.5
CVE-2024-30059

Microsoft Intune for Android Mobile Application Management Tampering Vulnerability

Fix: 5.0.6215.0+
Fix from $1,600 2024-05-14
Unclassified MEDIUM 6.5
CVE-2024-33647

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in the affected application lacks …

Mitigation only
Fix from $1,600 2024-05-14
Vikbooking Hotel Booking Engine \& Pms MEDIUM 5.9
CVE-2024-2749

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings,…

Fix: 1.6.8+
Fix from $1,600 2024-05-14