Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Mezzanine CRITICAL 9.8
CVE-2024-25169

An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.

No fix yet
Fix from $2,300 2024-02-28
Sitefinity MEDIUM 6.5
CVE-2024-1632

Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.

Fix: 13.3.7649 / 14.4.8135+
Fix from $1,600 2024-02-28
Elastic Cloud Storage MEDIUM 6.5
CVE-2024-22459

Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. …

Fix: 3.6.2.6 / 3.7.0.7+
Fix from $1,600 2024-02-28
Wordpress Access Control MEDIUM 5.3
CVE-2024-0975

The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via t…

Fix: after 4.0.13
Fix from $1,600 2024-02-28
Under Construction \/ Maintenance Mode MEDIUM 5.3
CVE-2024-1476

The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and…

Fix: after 2.6
Fix from $1,600 2024-02-28
Zenml HIGH 8.8
CVE-2024-25723EPSS 71%

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_o…

Fix: 0.42.2 / 0.44.4+
Fix from $1,950 2024-02-27
Anythingllm HIGH 7.1
CVE-2024-0551

Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been gran…

Fix: 1.0.0+
Fix from $1,950 2024-02-27
Fedora MEDIUM 5.3
CVE-2024-24568

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules insp…

Fix: 7.0.3+
Fix from $1,600 2024-02-26
Ethernet Controller I225 It Firmware HIGH 8.4
CVE-2021-33162

Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated us…

Fix: 1.87 / 29.0.1+
Fix from $1,950 2024-02-23
Simple Voting System MEDIUM 5.3
CVE-2024-1823

A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability is an unknown functionality of…

No fix yet
Fix from $1,600 2024-02-23
Agro School Management System HIGH 8.8
CVE-2024-25251

code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.

No fix yet
Fix from $1,950 2024-02-22
Unified Intelligence Center HIGH 7.1
CVE-2024-20325

A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data i…

Fix: 12.5 / 12.6+
Fix from $1,950 2024-02-21
Php Mysql User Signup Login System CRITICAL 9.8
CVE-2024-1701

A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown…

No fix yet
Fix from $2,300 2024-02-21
macOS MEDIUM 5.5
CVE-2023-42945

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Blue…

Mitigation only
Fix from $1,600 2024-02-21
macOS MEDIUM 5.5
CVE-2023-42853

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may b…

Fix: 12.7.1 / 13.6.1+
Fix from $1,600 2024-02-21
macOS MEDIUM 5.5
CVE-2023-42859

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be ab…

Fix: 12.7.1 / 13.6.1+
Fix from $1,600 2024-02-21
macOS HIGH 8.6
CVE-2023-42838

An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2…

Fix: 12.7.2 / 13.6.3+
Fix from $1,950 2024-02-21
Chrome HIGH 8.8
CVE-2024-1675EPSS 11%

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a…

Fix: 122.0.6261.57+
Fix from $1,950 2024-02-21
Tx9 Firmware HIGH 8.8
CVE-2023-47422

An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.…

No fix yet
Fix from $1,950 2024-02-20
Spring Security HIGH 7.4
CVE-2024-22234

In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it di…

Fix: 6.1.7 / 6.2.2+
Fix from $1,950 2024-02-20
Digital Experience Platform MEDIUM 6.3
CVE-2022-45320

Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users…

Fix: 7.2 / 7.4.3.16+
Fix from $1,600 2024-02-20
Fast Dds HIGH 8.1
CVE-2023-50257

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with th…

Fix: 2.6.7 / 2.10.3+
Fix from $1,950 2024-02-19
Moodle MEDIUM 5.3
CVE-2024-25980

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only prov…

Fix: 4.1.9 / 4.2.6+
Fix from $1,600 2024-02-19
Moodle MEDIUM 5.3
CVE-2024-25981

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only…

Fix: 4.1.9 / 4.2.6+
Fix from $1,600 2024-02-19
Laborofficefree MEDIUM 5.5
CVE-2024-1343

A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to r…

Mitigation only
Fix from $1,600 2024-02-19
Emui HIGH 7.5
CVE-2023-52375

Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2024-02-18
Emui HIGH 7.7
CVE-2023-52367

Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability an…

No fix yet
Fix from $1,950 2024-02-18
Customer Interaction History MEDIUM 6.1
CVE-2024-20951

Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are…

Fix: after 12.2.13
Fix from $1,600 2024-02-17
Weblogic Server HIGH 8.6
CVE-2024-20927

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $1,950 2024-02-17
Application Object Library MEDIUM 6.5
CVE-2024-20929

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are af…

Fix: after 12.2.13
Fix from $1,600 2024-02-17