Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Codeium HIGH 7.5
CVE-2024-28120

codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check …

No fix yet
Fix from $1,950 2024-03-11
Winmail HIGH 8.8
CVE-2024-25501

An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.

Fix: after 7.1
Fix from $1,950 2024-03-09
Automated Mess Management System CRITICAL 9.8
CVE-2024-2281

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been declared as critical. This vulnerability affects unknown code…

Mitigation only
Fix from $2,300 2024-03-08
macOS MEDIUM 5.5
CVE-2024-23266

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be ab…

Fix: 12.7.4 / 13.6.5+
Fix from $1,600 2024-03-08
macOS MEDIUM 5.5
CVE-2024-23267

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be ab…

Fix: 12.7.4 / 13.6.5+
Fix from $1,600 2024-03-08
Ipad Os HIGH 8.6
CVE-2024-0258

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A…

Fix: 10.4 / 14.4+
Fix from $1,950 2024-03-08
Freertos HIGH 7.8
CVE-2024-28115

FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local priv…

Fix: 10.6.2+
Fix from $1,950 2024-03-07
Unclassified CRITICAL 9.1
CVE-2023-51786

An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive inf…

Mitigation only
Fix from $2,300 2024-03-07
Re160 Firmware CRITICAL 9.8
CVE-2023-38945

Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_p…

No fix yet
Fix from $2,300 2024-03-06
Re160 Firmware HIGH 8.8
CVE-2023-38946

An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access control and gain complete access …

No fix yet
Fix from $1,950 2024-03-06
Tl Sg2210p Firmware HIGH 8.8
CVE-2023-43318

TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' value…

Mitigation only
Fix from $1,950 2024-03-06
Maintenance Mode MEDIUM 5.3
CVE-2024-1478

The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST AP…

Fix: 3.0.2+
Fix from $1,600 2024-03-05
Password Protected Store For Woocommerce MEDIUM 5.3
CVE-2024-1088

The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin…

Fix: 2.3+
Fix from $1,600 2024-03-05
Anythingllm HIGH 7.2
CVE-2024-0795

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from…

Fix: 1.0.0+
Fix from $1,950 2024-03-02
Book Store Management System CRITICAL 9.8
CVE-2023-49543

Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions withou…

No fix yet
Fix from $2,300 2024-03-01
Customer Support System HIGH 7.5
CVE-2023-49545

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application witho…

No fix yet
Fix from $1,950 2024-03-01
Unclassified CRITICAL 9.4
CVE-2024-21767

A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request.

No fix yet
Fix from $2,300 2024-03-01
E2000 Firmware HIGH 8.8
CVE-2024-27497EPSS 27%

Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

No fix yet
Fix from $1,950 2024-03-01
Datacube3 Firmware CRITICAL 9.8
CVE-2024-25830EPSS 24%

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker…

No fix yet
Fix from $2,300 2024-02-29
Nx Os MEDIUM 5.8
CVE-2024-20291

A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalon…

Mitigation only
Fix from $1,600 2024-02-29
Wp Maintenance MEDIUM 5.3
CVE-2024-1472

The WP Maintenance plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.1.6 via the REST API. This make…

Fix: 6.1.7+
Fix from $1,600 2024-02-29
Coming Soon Maintenance Mode MEDIUM 5.3
CVE-2024-1475

The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via…

Fix: 1.0.6+
Fix from $1,600 2024-02-29
Woo Czech MEDIUM 5.3
CVE-2024-1492

The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta …

Fix: 4.0.9+
Fix from $1,600 2024-02-29
Sunshine Photo Cart MEDIUM 5.3
CVE-2024-1294

The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions…

Fix: 3.1+
Fix from $1,600 2024-02-29
Customer Reviews For Woocommerce MEDIUM 5.3
CVE-2024-1044

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the…

Fix: 5.39.0+
Fix from $1,600 2024-02-29
My Private Site MEDIUM 5.3
CVE-2024-0978

The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.14 via the REST AP…

Fix: 3.1.0+
Fix from $1,600 2024-02-29
Json Jwt HIGH 8.4
CVE-2023-51774

The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE …

No fix yet
Fix from $1,950 2024-02-29
Couchbase Server CRITICAL 9.8
CVE-2023-49930

An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.

Fix: 7.2.4+
Fix from $2,300 2024-02-29
Couchbase Server CRITICAL 9.8
CVE-2023-49931

An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.

Fix: 7.2.4+
Fix from $2,300 2024-02-29
Worldserver CRITICAL 9.8
CVE-2022-34270

An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.

Fix: 11.7.3+
Fix from $2,300 2024-02-29