Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.1 CVE-2024-42514 A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct a… Micontact Center Business after 10.1.0.4 Fix from $1,9502024-10-01 MEDIUM 6.5 CVE-2024-45408 eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated u… Elabftw 5.1.0+ Fix from $1,6002024-10-01 HIGH 8.8 CVE-2024-46280 PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak credentials for a root-level a… Mitigation only Fix from $1,9502024-09-30 MEDIUM 5.3 CVE-2024-9321 A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue affects some unknown process… Railway Reservation System No fix yet Fix from $1,6002024-09-29 HIGH 8.1 CVE-2024-46097 TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental … Testlink No fix yet Fix from $1,9502024-09-27 HIGH 8.8 CVE-2024-45982 A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted pa… Mitigation only Fix from $1,9502024-09-26 CRITICAL 9.1 CVE-2024-46627 Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests. Mitigation only Fix from $2,3002024-09-26 HIGH 7.5 CVE-2024-44860 An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted r… Solvait No fix yet Fix from $1,9502024-09-26 HIGH 8.4 CVE-2024-41605 In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse vi… Mitigation only Fix from $1,9502024-09-26 MEDIUM 5.4 CVE-2024-42406 Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived c… Mattermost Server 9.5.9 / 9.9.3+ Fix from $1,6002024-09-26 MEDIUM 5.8 CVE-2024-20465 A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series S… iOS Mitigation only Fix from $1,6002024-09-25 HIGH 7.6 CVE-2024-46607 Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password v… Icecms after 3.4.7 Fix from $1,9502024-09-25 HIGH 7.5 CVE-2024-46609 An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and re… Icecms after 3.4.7 Fix from $1,9502024-09-25 HIGH 7.5 CVE-2024-46610 An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a… Icecms after 3.4.7 Fix from $1,9502024-09-25 CRITICAL 9.8 CVE-2024-42797 An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnera… Music Management System No fix yet Fix from $2,3002024-09-25 CRITICAL 9.8 CVE-2024-45489 Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of … Mitigation only Fix from $2,3002024-09-20 MEDIUM 5.3 CVE-2024-9003 A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadCo… Jflow Mitigation only Fix from $1,6002024-09-19 HIGH 7.8 CVE-2024-38016 Microsoft Office Visio Remote Code Execution Vulnerability 365 Apps Patch available Fix from $1,9502024-09-19 MEDIUM 5.0 CVE-2024-46990 Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.… Directus 10.13.3 / 11.1.0+ Fix from $1,6002024-09-18 MEDIUM 5.9 CVE-2024-42796 An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerabil… Music Management System No fix yet Fix from $1,6002024-09-16 HIGH 7.8 CVE-2024-34543 Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of pr… Raid Web Console Mitigation only Fix from $1,9502024-09-16 MEDIUM 5.7 CVE-2024-36247 Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable denial of service via adjacen… Raid Web Console Mitigation only Fix from $1,6002024-09-16 MEDIUM 5.7 CVE-2024-36261 Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service vi… Raid Web Console Mitigation only Fix from $1,6002024-09-16 MEDIUM 5.5 CVE-2024-28170 Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via lo… Raid Web Console Mitigation only Fix from $1,6002024-09-16 MEDIUM 5.7 CVE-2024-32940 Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of servic… Raid Web Console Mitigation only Fix from $1,6002024-09-16 HIGH 7.5 CVE-2023-43626 Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via l… Mitigation only Fix from $1,9502024-09-16 MEDIUM 5.3 CVE-2024-39772 Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality scre… Mattermost Desktop 5.9.0+ Fix from $1,6002024-09-16 HIGH 8.8 CVE-2024-8779 OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regu… Omflow 1.2.1.3+ Fix from $1,9502024-09-16 MEDIUM 6.5 CVE-2024-8269 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions u… Mstore Api 4.15.4+ Fix from $1,6002024-09-13 HIGH 8.8 CVE-2024-44571 RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php. Rely Pcie Firmware after 23.1.0 Fix from $1,9502024-09-11