Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Ipados MEDIUM 5.5
CVE-2024-27841

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disc…

Fix: 14.5 / 17.5+
Fix from $1,600 2024-05-14
Filemaker Server HIGH 7.5
CVE-2024-27790

Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. Thi…

Fix: 20.3.2+
Fix from $1,950 2024-05-14
Unclassified HIGH 8.8
CVE-2022-32507

An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged …

Mitigation only
Fix from $1,950 2024-05-14
Android HIGH 7.8
CVE-2024-0025

In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local esc…

Patch available
Fix from $1,950 2024-05-07
Unclassified HIGH 7.5
CVE-2024-29207

An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. Affected Prod…

Mitigation only
Fix from $1,950 2024-05-07
Fastconnect 6200 Firmware HIGH 7.8
CVE-2024-23351

Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.

Patch available
Fix from $1,950 2024-05-06
Wings MEDIUM 6.4
CVE-2024-34068

Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the prev…

Fix: 1.11.2+
Fix from $1,600 2024-05-03
Unclassified MEDIUM 6.8
CVE-2024-34404

A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, onl…

Mitigation only
Fix from $1,600 2024-05-03
Unclassified HIGH 8.4
CVE-2024-33396

An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

Mitigation only
Fix from $1,950 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-1678

The Subway – Private Site Option plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via…

Mitigation only
Fix from $1,600 2024-05-02
Analytify Google Analytics Dashboard MEDIUM 5.3
CVE-2024-1584

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of…

Fix: 5.2.4+
Fix from $1,600 2024-05-02
Unclassified CRITICAL 9.1
CVE-2024-31967

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit t…

Mitigation only
Fix from $2,300 2024-05-02
Unclassified HIGH 7.5
CVE-2024-31964

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit t…

Mitigation only
Fix from $1,950 2024-05-02
Unclassified MEDIUM 6.2
CVE-2024-33393

An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token compo…

Mitigation only
Fix from $1,600 2024-05-01
Unclassified MEDIUM 5.3
CVE-2024-22830

Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control when handling system resources.…

Mitigation only
Fix from $1,600 2024-05-01
Openmanage Enterprise MEDIUM 6.5
CVE-2024-28978

Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged remote attacker could potenti…

Mitigation only
Fix from $1,600 2024-05-01
Scadapro Server MEDIUM 5.5
CVE-2024-3746

The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, …

Mitigation only
Fix from $1,600 2024-04-30
Unclassified CRITICAL 9.8
CVE-2023-49473

Shenzhen JF6000 Cloud Media Collaboration Processing Platform firmware version V1.2.0 and software version V2.0.0 build 6245 is vulnerable to Incorre…

Mitigation only
Fix from $2,300 2024-04-30
Unclassified HIGH 7.6
CVE-2024-4225

Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can …

Mitigation only
Fix from $1,950 2024-04-30
Jerryscript MEDIUM 5.1
CVE-2024-33260

Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at jerry-core/parser/js/js-parser-…

No fix yet
Fix from $1,600 2024-04-26
Backup Exec HIGH 7.8
CVE-2024-33673

An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search …

Fix: 23.0+
Fix from $1,950 2024-04-26
Zammad HIGH 8.6
CVE-2024-33666

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via…

Fix: 6.3.0+
Fix from $1,950 2024-04-26
Safari MEDIUM 6.5
CVE-2024-23271

A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS…

Fix: 10.3 / 14.3+
Fix from $1,600 2024-04-24
Unclassified HIGH 8.4
CVE-2023-38297

An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufacturers. Certain software buil…

Mitigation only
Fix from $1,950 2024-04-22
Unclassified HIGH 8.8
CVE-2023-38298

Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by any loc…

Mitigation only
Fix from $1,950 2024-04-22
Unclassified HIGH 8.0
CVE-2023-38296

Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any local app on th…

Mitigation only
Fix from $1,950 2024-04-22
Hugegraph CRITICAL 9.8
CVE-2024-27348 KEVEPSS 99%

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & …

Fix: 1.3.0+
Fix from $2,300 2024-04-22
Pathpilot Controller MEDIUM 6.5
CVE-2024-22807

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the flash memory, causing the machi…

Mitigation only
Fix from $1,600 2024-04-22
Pathpilot Controller HIGH 8.2
CVE-2024-22811

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communicatio…

Mitigation only
Fix from $1,950 2024-04-22
Flusity CRITICAL 9.8
CVE-2024-32418

An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.

No fix yet
Fix from $2,300 2024-04-22