Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified HIGH 7.1
CVE-2023-20587

Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.

Mitigation only
Fix from $1,950 2024-02-13
Epyc 7773x Firmware MEDIUM 6.0
CVE-2023-31346

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

Mitigation only
Fix from $1,600 2024-02-13
Event Management And Registration HIGH 8.8
CVE-2024-24751

sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access…

Patch available
Fix from $1,950 2024-02-13
Entra Jira Sso Plugin CRITICAL 9.8
CVE-2024-21401

Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability

Fix: 1.1.2+
Fix from $2,300 2024-02-13
Azure Kubernetes Service CRITICAL 9.0
CVE-2024-21376

Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

Patch available
Fix from $2,300 2024-02-13
Azure Site Recovery CRITICAL 9.3
CVE-2024-21364

Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2024-02-13
Skype For Business Server MEDIUM 5.7
CVE-2024-20695

Skype for Business Information Disclosure Vulnerability

Patch available
Fix from $1,600 2024-02-13
Min HIGH 8.8
CVE-2024-25677

In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resource…

Mitigation only
Fix from $1,950 2024-02-09
Openobserve HIGH 8.8
CVE-2024-24830

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability …

Fix: 0.8.0+
Fix from $1,950 2024-02-08
Openobserve MEDIUM 6.5
CVE-2024-25106

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulne…

Fix: 0.8.0+
Fix from $1,600 2024-02-08
Daily Habit Tracker CRITICAL 9.8
CVE-2024-24496EPSS 20%

An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-t…

No fix yet
Fix from $2,300 2024-02-08
Simple Page Access Restriction MEDIUM 5.3
CVE-2024-0965

The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 …

Fix: after 1.0.21
Fix from $1,600 2024-02-08
Graylog HIGH 8.8
CVE-2024-24824EPSS 34%

Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded…

Fix: 5.1.11 / 5.2.4+
Fix from $1,950 2024-02-07
Open Forms MEDIUM 5.9
CVE-2024-24771

Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authe…

Fix: 2.2.9 / 2.3.7+
Fix from $1,600 2024-02-07
Kibana MEDIUM 6.5
CVE-2024-23446

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (F…

Fix: 8.12.1+
Fix from $1,600 2024-02-07
Network Drive Connector MEDIUM 6.5
CVE-2024-23447

An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allo…

Fix: 8.12.1+
Fix from $1,600 2024-02-07
Encryption HIGH 7.8
CVE-2023-32479

Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation v…

Fix: 11.9.0+
Fix from $1,950 2024-02-06
Qam8255p Firmware HIGH 7.8
CVE-2023-43517

Memory corruption in Automotive Multimedia due to improper access control in HAB.

No fix yet
Fix from $1,950 2024-02-06
Armember MEDIUM 5.3
CVE-2024-0969

The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This…

Fix: after 4.0.24
Fix from $1,600 2024-02-05
Profile Builder HIGH 7.5
CVE-2024-0324

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized mod…

Fix: after 3.10.8
Fix from $1,950 2024-02-05
Phpmyfaq MEDIUM 6.5
CVE-2024-22202

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacke…

Fix: 3.2.5+
Fix from $1,600 2024-02-05
Lantime Firmware MEDIUM 6.5
CVE-2021-46903

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. An admin can …

Fix: 6.24.029 / 7.04.008+
Fix from $1,600 2024-02-04
Reprise License Manager HIGH 7.5
CVE-2023-44031

Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in…

Fix: 16.0+
Fix from $1,950 2024-02-03
Soar Qradar Plugin App HIGH 8.8
CVE-2023-38263

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM …

Fix: 5.0.3+
Fix from $1,950 2024-02-02
Maximo Asset Management CRITICAL 9.8
CVE-2023-32333

IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 2550…

Patch available
Fix from $2,300 2024-02-02
Feverwarn Firmware HIGH 8.8
CVE-2023-47867

MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and comp…

Mitigation only
Fix from $1,950 2024-02-01
Openbi CRITICAL 9.8
CVE-2024-1114

A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function dlfile of the file /applicat…

Fix: after 1.0.8
Fix from $2,300 2024-01-31
Lobe Chat MEDIUM 5.3
CVE-2024-24566

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is pass…

Fix: 0.122.4+
Fix from $1,600 2024-01-31
Vantage6 CRITICAL 9.8
CVE-2024-21653

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). …

Fix: 4.2.0+
Fix from $2,300 2024-01-30
Employee Management System HIGH 8.8
CVE-2024-1011

A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability affects unknown code of the …

No fix yet
Fix from $1,950 2024-01-29