Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Javascript CRITICAL 9.8
CVE-2024-22206

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth(…

Fix: 4.29.3+
Fix from $2,300 2024-01-12
Paragon Active Assurance Control Center HIGH 7.5
CVE-2024-21589

An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated network-based atta…

Mitigation only
Fix from $1,950 2024-01-12
Edge Chromium MEDIUM 6.3
CVE-2024-20675

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Fix: 120.0.2210.133+
Fix from $1,600 2024-01-11
Dsmall CRITICAL 9.8
CVE-2024-0415

A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the fil…

Fix: after 6.1.0
Fix from $2,300 2024-01-11
Dskms CRITICAL 9.8
CVE-2024-0413

A vulnerability was found in DeShang DSKMS up to 3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file publ…

Fix: after 3.1.2
Fix from $2,300 2024-01-11
Dscms CRITICAL 9.8
CVE-2024-0414

A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install…

Fix: after 3.1.2
Fix from $2,300 2024-01-11
Dsmall HIGH 7.5
CVE-2024-0411

A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/insta…

Fix: after 6.1.0
Fix from $1,950 2024-01-11
Dsshop CRITICAL 9.8
CVE-2024-0412

A vulnerability was found in DeShang DSShop up to 3.1.0. It has been declared as problematic. This vulnerability affects unknown code of the file pub…

Mitigation only
Fix from $2,300 2024-01-11
Scalefusion HIGH 8.8
CVE-2023-50159

In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This i…

No fix yet
Fix from $1,950 2024-01-11
Scalefusion MEDIUM 6.8
CVE-2023-51751

ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launch…

Mitigation only
Fix from $1,600 2024-01-11
Elements Kit Elementor Addons MEDIUM 5.3
CVE-2023-6582

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via…

Fix: 3.0.4+
Fix from $1,600 2024-01-11
Customer Management Framework MEDIUM 6.5
CVE-2024-21666

The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing auto…

Fix: 4.0.6+
Fix from $1,600 2024-01-11
Customer Management Framework MEDIUM 6.5
CVE-2024-21667

pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorize…

Fix: 4.0.6+
Fix from $1,600 2024-01-11
macOS MEDIUM 5.5
CVE-2022-42816

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of …

Fix: 13.0+
Fix from $1,600 2024-01-10
Fortiportal HIGH 8.8
CVE-2023-46712

A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to es…

Fix: after 7.2.1
Fix from $1,950 2024-01-10
N200re V5 Firmware CRITICAL 9.1
CVE-2022-46025

Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system inform…

Patch available
Fix from $2,300 2024-01-10
R15 Firmware MEDIUM 5.3
CVE-2023-41603

D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any servi…

Fix: after 1.08.02
Fix from $1,600 2024-01-10
Ssm Shiro Blog HIGH 7.5
CVE-2024-0356

A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionalit…

No fix yet
Fix from $1,950 2024-01-10
Dso2o HIGH 7.5
CVE-2024-0358

A vulnerability was found in DeShang DSO2O up to 4.1.0. It has been classified as critical. This affects an unknown part of the file /install/install…

Fix: after 4.1.0
Fix from $1,950 2024-01-10
Windows 10 1507 HIGH 7.0
CVE-2024-20657

Windows Group Policy Elevation of Privilege Vulnerability

Fix: 10.0.10240.20402 / 10.0.14393.6614+
Fix from $1,950 2024-01-09
T6 Firmware MEDIUM 6.5
CVE-2023-7223

A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cst…

No fix yet
Fix from $1,600 2024-01-09
Bastion HIGH 7.5
CVE-2023-49961

WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.

Fix: 9.0.10 / 10.0.6+
Fix from $1,950 2024-01-08
Pyload HIGH 7.5
CVE-2024-21644EPSS 42%

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask…

Fix: after 0.4.9
Fix from $1,950 2024-01-08
Ox App Suite HIGH 8.1
CVE-2023-29051

User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature …

Fix: 7.10.6+
Fix from $1,950 2024-01-08
Maxview Storage Manager CRITICAL 10.0
CVE-2024-22216

In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote s…

Fix: after 4.14.00.26064
Fix from $2,300 2024-01-08
Wp Members MEDIUM 6.5
CVE-2023-6733

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via…

Fix: after 3.4.8
Fix from $1,600 2024-01-04
Dryice Myxalytics MEDIUM 6.5
CVE-2023-50343

HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Adm…

Mitigation only
Fix from $1,600 2024-01-03
Dryice Myxalytics MEDIUM 5.4
CVE-2023-50344

HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download cert…

Mitigation only
Fix from $1,600 2024-01-03
Dryice Myxalytics HIGH 7.5
CVE-2023-50341

HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, refl…

Mitigation only
Fix from $1,950 2024-01-03
Bookmark HIGH 8.1
CVE-2023-7193

A vulnerability was found in MTab Bookmark up to 1.2.6 and classified as critical. This issue affects some unknown processing of the file public/inst…

Fix: after 1.2.6
Fix from $1,950 2023-12-31