Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Apollo Vx20 Firmware HIGH 7.5
CVE-2024-25736

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.

Fix: 1.3.58+
Fix from $1,950 2024-03-27
Unclassified HIGH 8.8
CVE-2023-50702

Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have…

Mitigation only
Fix from $1,950 2024-03-26
Seq CRITICAL 9.1
CVE-2024-29866

Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate…

Fix: 2023.4.11151 / 2024.1.11146+
Fix from $2,300 2024-03-21
Dreamer Cms MEDIUM 6.5
CVE-2024-25811

An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.

No fix yet
Fix from $1,600 2024-03-21
Customer Support System HIGH 8.8
CVE-2023-49978

Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for…

No fix yet
Fix from $1,950 2024-03-21
Axigen Mail Server CRITICAL 9.1
CVE-2020-26942

An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminP…

Fix: 10.3.1.27 / 10.3.3.1+
Fix from $2,300 2024-03-21
Coming Soon \& Maintenance Mode MEDIUM 5.3
CVE-2024-1473

The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.9…

Fix: after 1.0.99
Fix from $1,600 2024-03-20
Alma Blog MEDIUM 6.5
CVE-2024-1144

Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an unauthentica…

Fix: after 2.1.10
Fix from $1,600 2024-03-19
Coldfusion HIGH 7.4
CVE-2024-20767 KEVEPSS 99%

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system r…

Mitigation only
Fix from $1,950 2024-03-18
Unclassified CRITICAL 9.1
CVE-2021-47155

The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allo…

Mitigation only
Fix from $2,300 2024-03-18
Tg Firmware HIGH 7.5
CVE-2022-47037

Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.

Fix: 2.1.1+
Fix from $1,950 2024-03-18
Unclassified CRITICAL 9.8
CVE-2022-47036

Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash.…

Mitigation only
Fix from $2,300 2024-03-18
Hostel Management System MEDIUM 6.5
CVE-2024-2481

A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected is an unknown function of the …

No fix yet
Fix from $1,600 2024-03-15
Ultimateimagetool CRITICAL 9.8
CVE-2024-28390

An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sens…

Fix: 2.2.01+
Fix from $2,300 2024-03-14
Ios Xr MEDIUM 5.8
CVE-2024-20322

A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an…

Mitigation only
Fix from $1,600 2024-03-13
Unclassified MEDIUM 5.8
CVE-2024-20315

A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unaut…

Mitigation only
Fix from $1,600 2024-03-13
Avada MEDIUM 6.5
CVE-2024-1668

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and inc…

Fix: 7.11.6+
Fix from $1,600 2024-03-13
Maintenance Page MEDIUM 5.3
CVE-2024-1462

The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. T…

Fix: 1.0.9+
Fix from $1,600 2024-03-13
Restrict User Access MEDIUM 5.3
CVE-2024-0687

The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Exposure in all versions up to,…

Fix: 2.6+
Fix from $1,600 2024-03-13
Duitku Payment Gateway MEDIUM 5.3
CVE-2024-0631

The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_dui…

Fix: after 2.11.4
Fix from $1,600 2024-03-13
Lifterlms MEDIUM 5.3
CVE-2024-0377

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit…

Fix: 7.5.2+
Fix from $1,600 2024-03-13
Download Manager MEDIUM 5.3
CVE-2023-6785

The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and includ…

Fix: 3.2.85+
Fix from $1,600 2024-03-13
A8000ru Firmware HIGH 8.0
CVE-2024-28338

A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.

No fix yet
Fix from $1,950 2024-03-12
Intune Company Portal MEDIUM 6.6
CVE-2024-26201

Microsoft Intune Linux Agent Elevation of Privilege Vulnerability

Fix: 1.2402.12+
Fix from $1,600 2024-03-12
Azure Data Studio HIGH 7.3
CVE-2024-26203

Azure Data Studio Elevation of Privilege Vulnerability

Fix: 1.48.0+
Fix from $1,950 2024-03-12
Windows 10 1507 HIGH 7.8
CVE-2024-21436

Windows Installer Elevation of Privilege Vulnerability

Fix: 10.0.10240.20526 / 10.0.14393.6796+
Fix from $1,950 2024-03-12
Software For Open Networking In The Cloud HIGH 7.8
CVE-2024-21418

Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability

Fix: 20181130.106 / 20191130.89+
Fix from $1,950 2024-03-12
Fortimanager CRITICAL 9.8
CVE-2023-36554

A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.…

Fix: after 7.2.3
Fix from $2,300 2024-03-12
Sinema Remote Connect Server CRITICAL 9.8
CVE-2022-32257

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that la…

Fix: 3.2+
Fix from $2,300 2024-03-12
Skysea Client View HIGH 7.8
CVE-2024-21805

Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnera…

Fix: 19.300.09h+
Fix from $1,950 2024-03-12