Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Embrace HIGH 7.5
CVE-2024-31846

An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unautho…

No fix yet
Fix from $1,950 2024-04-19
Connections MEDIUM 6.5
CVE-2024-30107

HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

Mitigation only
Fix from $1,600 2024-04-18
Smart Reader Firmware HIGH 7.5
CVE-2023-43491

An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A…

No fix yet
Fix from $1,950 2024-04-17
Smart Reader Firmware HIGH 7.5
CVE-2023-45209

An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEM…

No fix yet
Fix from $1,950 2024-04-17
Smart Reader Firmware HIGH 8.8
CVE-2023-45744

A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A speci…

No fix yet
Fix from $1,950 2024-04-17
Dolibarr Erp\/crm HIGH 7.5
CVE-2024-31503

Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CS…

Fix: 19.0.1+
Fix from $1,950 2024-04-17
Publiccms HIGH 8.8
CVE-2024-31759

An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.

No fix yet
Fix from $1,950 2024-04-16
Vm Virtualbox HIGH 8.8
CVE-2024-21113

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.16+
Fix from $1,950 2024-04-16
Vm Virtualbox HIGH 8.8
CVE-2024-21114

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.16+
Fix from $1,950 2024-04-16
Vm Virtualbox HIGH 8.8
CVE-2024-21115

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.16+
Fix from $1,950 2024-04-16
Vm Virtualbox MEDIUM 6.7
CVE-2024-21107

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.16+
Fix from $1,600 2024-04-16
Vm Virtualbox HIGH 7.3
CVE-2024-21110

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.16+
Fix from $1,950 2024-04-16
Vm Virtualbox HIGH 8.8
CVE-2024-21112

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.16+
Fix from $1,950 2024-04-16
Vm Virtualbox HIGH 7.8
CVE-2024-21103

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.16+
Fix from $1,950 2024-04-16
Agile Product Lifecycle Management For Process MEDIUM 6.5
CVE-2024-21091

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The supported v…

Mitigation only
Fix from $1,600 2024-04-16
Bi Publisher MEDIUM 5.8
CVE-2024-21084

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Service Gateway). Supported versions that are affected are 7.0.0.0.…

Mitigation only
Fix from $1,600 2024-04-16
Trade Management HIGH 7.5
CVE-2024-21074

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Finance LOV). Supported versions that are affected are 1…

Fix: after 12.2.13
Fix from $1,950 2024-04-16
Trade Management HIGH 7.5
CVE-2024-21076

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Offer LOV). Supported versions that are affected are 12.…

Fix: after 12.2.13
Fix from $1,950 2024-04-16
Enterprise Manager Base Platform HIGH 8.8
CVE-2024-21067

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Host Management). The supported versi…

Mitigation only
Fix from $1,950 2024-04-16
Workflow CRITICAL 9.1
CVE-2024-21071

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affect…

Fix: after 12.2.13
Fix from $2,300 2024-04-16
Ds 600 Firmware HIGH 7.5
CVE-2024-24485

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command.

Mitigation only
Fix from $1,950 2024-04-15
Ds 600 Firmware CRITICAL 9.1
CVE-2024-24486

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.

Mitigation only
Fix from $2,300 2024-04-15
Ds 600 Firmware MEDIUM 6.8
CVE-2024-24487

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using t…

Mitigation only
Fix from $1,600 2024-04-15
Evolution HIGH 7.5
CVE-2024-29842

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_A…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Evolution HIGH 7.5
CVE-2024-29843

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, …

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Evolution HIGH 8.8
CVE-2024-29837

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attack…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Evolution HIGH 7.5
CVE-2024-29839

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_C…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Evolution HIGH 7.5
CVE-2024-29840

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_P…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Evolution HIGH 7.5
CVE-2024-29841

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_K…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Evolution CRITICAL 9.8
CVE-2024-29836

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthent…

Fix: after 2.04.560
Fix from $2,300 2024-04-15