Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified CRITICAL 9.8
CVE-2024-3765

A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, AHB7004T-MHV2, AHB8032F-LME an…

No fix yet
Fix from $2,300 2024-04-14
Re7000 Firmware HIGH 8.8
CVE-2024-25852EPSS 17%

Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control functio…

No fix yet
Fix from $1,950 2024-04-11
Chuanhuchatgpt HIGH 7.5
CVE-2024-2217

gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is pr…

Patch available
Fix from $1,950 2024-04-10
Unclassified MEDIUM 5.4
CVE-2024-2731

Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages that expose sensitive informa…

Mitigation only
Fix from $1,600 2024-04-10
Unclassified HIGH 7.5
CVE-2024-1308

The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th…

Mitigation only
Fix from $1,950 2024-04-09
Unclassified MEDIUM 5.3
CVE-2024-0899

The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress i…

Mitigation only
Fix from $1,600 2024-04-09
Unclassified MEDIUM 5.3
CVE-2024-0626

The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t…

Mitigation only
Fix from $1,600 2024-04-09
Azure Kubernetes Service Confidential Containers CRITICAL 9.0
CVE-2024-29990EPSS 18%

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Fix: 0.3.4+
Fix from $2,300 2024-04-09
Azure Cyclecloud HIGH 8.8
CVE-2024-29993

Azure CycleCloud Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2024-04-09
Defender For Iot HIGH 7.2
CVE-2024-29054

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Fix: 24.1.3+
Fix from $1,950 2024-04-09
Defender For Iot HIGH 7.2
CVE-2024-29055

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Fix: 24.1.3+
Fix from $1,950 2024-04-09
Azure Arc Extension Microsoft.azstackhci.operator MEDIUM 6.2
CVE-2024-28917

Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability

Fix: 0.3.0-preview / 1.0.2620-162+
Fix from $1,600 2024-04-09
Windows 10 1507 MEDIUM 6.7
CVE-2024-26234

Proxy Driver Spoofing Vulnerability

Fix: 10.0.10240.20596 / 10.0.14393.6897+
Fix from $1,600 2024-04-09
Azure Compute Gallery MEDIUM 6.5
CVE-2024-21424

Azure Compute Gallery Elevation of Privilege Vulnerability

No fix yet
Fix from $1,600 2024-04-09
Ex200 Firmware MEDIUM 6.5
CVE-2024-31805

TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setT…

No fix yet
Fix from $1,600 2024-04-08
Harmonyos HIGH 7.5
CVE-2024-27895

Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,950 2024-04-08
Emui HIGH 7.5
CVE-2023-52537

Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect avai…

No fix yet
Fix from $1,950 2024-04-08
Emui HIGH 7.5
CVE-2024-30418

Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect…

Mitigation only
Fix from $1,950 2024-04-07
Mattermost Server MEDIUM 6.5
CVE-2024-2447

Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain ty…

Fix: 8.1.11 / 9.3.3+
Fix from $1,600 2024-04-05
Unclassified MEDIUM 5.9
CVE-2024-31207

Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.d…

Patch available
Fix from $1,600 2024-04-04
Tradepro MEDIUM 5.3
CVE-2023-36644

Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail…

No fix yet
Fix from $1,600 2024-04-04
Tradepro MEDIUM 5.3
CVE-2023-36643

Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in cu…

No fix yet
Fix from $1,600 2024-04-04
Unclassified MEDIUM 5.3
CVE-2024-1418

The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2 via the REST …

Mitigation only
Fix from $1,600 2024-04-04
Thingsboard MEDIUM 6.5
CVE-2024-3270

A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeat…

Fix: after 3.6.2
Fix from $1,600 2024-04-03
Alldata HIGH 7.5
CVE-2024-27605

Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system.

Mitigation only
Fix from $1,950 2024-04-02
Alldata CRITICAL 9.1
CVE-2024-27602

Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v…

Mitigation only
Fix from $2,300 2024-04-02
Semcms HIGH 7.2
CVE-2024-28405

SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin …

No fix yet
Fix from $1,950 2024-03-29
Fedora HIGH 8.2
CVE-2024-28960

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared m…

Fix: 2.28.8 / 3.6.0+
Fix from $1,950 2024-03-29
Aterm Wg1800hp4 Firmware MEDIUM 6.0
CVE-2024-28016

Improper Access Controlvulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, …

Mitigation only
Fix from $1,600 2024-03-28
Insightiq MEDIUM 6.5
CVE-2024-25962

Dell InsightIQ, version 5.0, contains an improper access control vulnerability. A remote low privileged attacker could potentially exploit this vulne…

Mitigation only
Fix from $1,600 2024-03-27