Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Cloudflare MEDIUM 6.5
CVE-2024-0212

The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged ac…

Fix: 4.12.3+
Fix from $1,600 2024-01-29
Cbs250 8t D Firmware HIGH 7.2
CVE-2024-20263

A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and B…

Fix: 2.5.9.54 / 3.4.0.17+
Fix from $1,950 2024-01-26
Ipados MEDIUM 5.5
CVE-2023-40528

This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS 17, macOS Ve…

Fix: 10.0 / 13.6.4+
Fix from $1,600 2024-01-23
Cloud MEDIUM 6.5
CVE-2024-23675

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST…

Fix: 9.0.8 / 9.1.3+
Fix from $1,600 2024-01-22
Artemis Java Test Sandbox HIGH 8.2
CVE-2024-23681

Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or S…

Fix: 1.11.2+
Fix from $1,950 2024-01-19
Vite HIGH 7.5
CVE-2024-23331

Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems usi…

Fix: 2.9.17 / 3.2.8+
Fix from $1,950 2024-01-19
Nuc P14e Laptop Element MEDIUM 5.5
CVE-2023-32544

Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may …

Fix: 1.1.45+
Fix from $1,600 2024-01-19
Uniswapfrontrunbot HIGH 7.5
CVE-2023-47034

A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors.

No fix yet
Fix from $1,950 2024-01-19
Smart S150 Firmware CRITICAL 9.8
CVE-2024-0712

A vulnerability was found in Byzoro Smart S150 Management Platform V31R02B15. It has been classified as critical. Affected is an unknown function of …

No fix yet
Fix from $2,300 2024-01-19
Language Server Protocol Integration CRITICAL 9.8
CVE-2024-22415

jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Serve…

Fix: 2.2.2+
Fix from $2,300 2024-01-18
Evolved Programmable Network Manager MEDIUM 6.7
CVE-2023-20260

A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, loc…

Fix: 3.10.4 / 7.1.1+
Fix from $1,600 2024-01-17
Live Encoder CRITICAL 9.8
CVE-2024-0642

Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the app…

Mitigation only
Fix from $2,300 2024-01-17
Shopware MEDIUM 6.5
CVE-2024-22407

Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations fo…

Fix: 6.5.7.4+
Fix from $1,600 2024-01-16
MySQL MEDIUM 5.5
CVE-2024-20969

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8…

Fix: after 8.2.0
Fix from $1,600 2024-01-16
Knowledge Management MEDIUM 6.1
CVE-2024-20948

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected …

Fix: after 12.2.13
Fix from $1,600 2024-01-16
Openjdk HIGH 7.4
CVE-2024-20952

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp…

Fix: 11.0.24 / 17.0.10+
Fix from $1,950 2024-01-16
One To One Fulfillment MEDIUM 6.1
CVE-2024-20936

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected a…

Fix: after 12.2.13
Fix from $1,600 2024-01-16
Istore MEDIUM 6.1
CVE-2024-20938

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: ECC). Supported versions that are affected are 12.2.3-12.2.13. Eas…

Fix: after 12.2.13
Fix from $1,600 2024-01-16
Debian Linux MEDIUM 5.9
CVE-2024-20926

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Sup…

Patch available
Fix from $1,600 2024-01-16
Graalvm HIGH 7.5
CVE-2024-20932

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp…

Patch available
Fix from $1,950 2024-01-16
Enterprise Manager HIGH 8.3
CVE-2024-20916

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported vers…

Patch available
Fix from $1,950 2024-01-16
Debian Linux HIGH 7.4
CVE-2024-20918

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo…

Patch available
Fix from $1,950 2024-01-16
Financial Services Analytical Applications Infrastructure HIGH 7.4
CVE-2023-21901

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: I…

Patch available
Fix from $1,950 2024-01-16
N350rt Firmware CRITICAL 9.1
CVE-2024-0570

A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $2,300 2024-01-16
Emui HIGH 7.5
CVE-2023-52099

Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service c…

No fix yet
Fix from $1,950 2024-01-16
Harmonyos HIGH 7.5
CVE-2023-52105

The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2024-01-16
Emui HIGH 7.5
CVE-2023-52114

Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.

No fix yet
Fix from $1,950 2024-01-16
Edx Platform HIGH 8.8
CVE-2024-22209

Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call e…

Fix: 2024-01-12+
Fix from $1,950 2024-01-13
Archive Storage Manager HIGH 7.5
CVE-2023-51070

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensiti…

No fix yet
Fix from $1,950 2024-01-13
Archive Storage Manager HIGH 7.5
CVE-2023-51065

Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and…

No fix yet
Fix from $1,950 2024-01-13