Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.5 CVE-2024-20343 A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlyin… Ios Xr Mitigation only Fix from $1,6002024-09-11 HIGH 7.8 CVE-2024-43492 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability Autoupdate 4.72+ Fix from $1,9502024-09-10 HIGH 8.5 CVE-2024-43479 Microsoft Power Automate Desktop Remote Code Execution Vulnerability Power Automate 2.41.178.24249 / 2.42.331.24249+ Fix from $1,9502024-09-10 CRITICAL 9.0 CVE-2024-38220 Azure Stack Hub Elevation of Privilege Vulnerability Azure Stack Hub 1.2311.1.22+ Fix from $2,3002024-09-10 CRITICAL 9.8 CVE-2024-37341 Microsoft SQL Server Elevation of Privilege Vulnerability Sql 2016 Azure Connect Feature Pack 13.0.6441.1 / 13.0.7040.1+ Fix from $2,3002024-09-10 CRITICAL 9.8 CVE-2023-37234 Loftware Spectrum through 4.6 has unprotected JMX Registry. Spectrum after 4.6 Fix from $2,3002024-09-10 HIGH 7.5 CVE-2024-37993 A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6B… Simatic Rf360r Firmware 1.1 / 2.2+ Fix from $1,9502024-09-10 MEDIUM 6.7 CVE-2024-39580 Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access … Insightiq 5.1.1+ Fix from $1,6002024-09-10 CRITICAL 9.1 CVE-2024-6796 In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated… Connex Health Portal 2024-08-30+ Fix from $2,3002024-09-09 MEDIUM 6.5 CVE-2024-42021 An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials. One 12.2.0.4093+ Fix from $1,6002024-09-07 MEDIUM 5.3 CVE-2024-42022 An incorrect permission assignment vulnerability allows an attacker to modify product configuration files. One 12.2.0.4093+ Fix from $1,6002024-09-07 HIGH 8.8 CVE-2024-42023 An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely. One 12.2.0.4093+ Fix from $1,9502024-09-07 MEDIUM 5.3 CVE-2023-30582 A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used… Mitigation only Fix from $1,6002024-09-07 HIGH 7.5 CVE-2023-30583 fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 2… Mitigation only Fix from $1,9502024-09-07 HIGH 7.5 CVE-2023-30587 A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspector module… Mitigation only Fix from $1,9502024-09-07 HIGH 8.1 CVE-2024-45170 An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use admin… C Mor Video Surveillance No fix yet Fix from $1,9502024-09-04 MEDIUM 5.4 CVE-2024-45313 Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-com… Overleaf 2024-07-17 / 2024-08-28+ Fix from $1,6002024-09-02 CRITICAL 9.8 CVE-2024-45522 Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages… Linen 2024-04-03+ Fix from $2,3002024-09-02 MEDIUM 6.5 CVE-2024-45509 In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not… Misp 2.4.197+ Fix from $1,6002024-09-01 CRITICAL 9.8 CVE-2024-45233 An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missi… Powermail 7.5.0 / 8.5.0+ Fix from $2,3002024-08-29 MEDIUM 5.5 CVE-2024-44913 An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulne… Exr No fix yet Fix from $1,6002024-08-28 MEDIUM 5.5 CVE-2024-44914 An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulne… Exr No fix yet Fix from $1,6002024-08-28 MEDIUM 5.5 CVE-2024-44915 An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulne… Exr No fix yet Fix from $1,6002024-08-28 MEDIUM 5.4 CVE-2024-8216 A vulnerability, which was classified as critical, has been found in nafisulbari/itsourcecode Insurance Management System 1.0. Affected by this issue… Life Insurance Management System Mitigation only Fix from $1,6002024-08-27 MEDIUM 5.3 CVE-2024-5814 A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful … Wolfssl after 5.7.0 Fix from $1,6002024-08-27 CRITICAL 9.8 CVE-2024-36068 An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to… Cloud Data Management 8.1.3 / 9.0.3+ Fix from $2,3002024-08-27 HIGH 8.8 CVE-2024-8164 A vulnerability was determined in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function rename of the file /Admin/Htt… Beikeshop after 1.5.5 Fix from $1,9502024-08-26 MEDIUM 5.4 CVE-2024-42766 Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php. Bus Ticket Reservation System Mitigation only Fix from $1,6002024-08-23 CRITICAL 9.8 CVE-2024-40766 KEVEPSS 18% An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource… Sonicos 5.9.2.14-13o / 6.5.2.8-2n+ Fix from $2,3002024-08-23 HIGH 7.5 CVE-2024-43477 Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable … Entra Id Mitigation only Fix from $1,9502024-08-23