Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2024-42772 An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated at… Hotel Management System No fix yet Fix from $1,9502024-08-22 CRITICAL 9.1 CVE-2024-42775 An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unau… Hotel Management System No fix yet Fix from $2,3002024-08-22 HIGH 7.2 CVE-2024-42776 Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php. Hotel Management System No fix yet Fix from $1,9502024-08-22 MEDIUM 5.4 CVE-2024-36441 Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are rece… Mitigation only Fix from $1,6002024-08-22 HIGH 7.6 CVE-2024-36443 Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP. Mitigation only Fix from $1,9502024-08-22 HIGH 7.2 CVE-2024-8071 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system adm… Mattermost 9.5.8 / 9.8.3+ Fix from $1,9502024-08-22 HIGH 8.8 CVE-2024-38175 An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges ov… Azure Managed Instance For Apache Cassandra Mitigation only Fix from $1,9502024-08-20 CRITICAL 9.8 CVE-2024-42919 eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport. Escan Management Console No fix yet Fix from $2,3002024-08-20 HIGH 7.5 CVE-2024-27187 Improper Access Controls allows backend users to overwrite their username when disallowed. Joomla\! 4.4.7 / 5.1.3+ Fix from $1,9502024-08-20 MEDIUM 6.5 CVE-2024-43409 Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform me… Ghost 5.89.5+ Fix from $1,6002024-08-20 CRITICAL 9.8 CVE-2024-42559 An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a val… Mitigation only Fix from $2,3002024-08-20 CRITICAL 9.8 CVE-2024-7921 A vulnerability has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805 and classified as problematic. Affect… Jielink\+ Jsotc2016 after 20240805 Fix from $2,3002024-08-19 CRITICAL 9.8 CVE-2024-7919 A vulnerability, which was classified as critical, has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. T… Jielink\+ Jsotc2016 after 20240805 Fix from $2,3002024-08-19 CRITICAL 9.8 CVE-2024-7920 A vulnerability, which was classified as problematic, was found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. Aff… Jielink\+ Jsotc2016 after 20240805 Fix from $2,3002024-08-19 HIGH 7.5 CVE-2024-6221 A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. T… Flask Cors Patch available Fix from $1,9502024-08-18 CRITICAL 9.8 CVE-2024-42967 Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the usernam… Lr350 Firmware No fix yet Fix from $2,3002024-08-15 MEDIUM 5.5 CVE-2024-28050 Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to poten… Arc A Graphics 31.0.101.4824+ Fix from $1,6002024-08-14 HIGH 7.9 CVE-2024-25576 improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege… Agilex 7 Fpga Firmware 24.1+ Fix from $1,9502024-08-14 HIGH 7.8 CVE-2024-26022 Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable esca… Aptio V Uefi Firmware Integrator Tools 5.05.04.0008 / 5.13.00.2106+ Fix from $1,9502024-08-14 HIGH 8.8 CVE-2024-24986 Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an auth… Ethernet 800 Series Controllers Driver 28.3+ Fix from $1,9502024-08-14 MEDIUM 5.5 CVE-2023-43489 Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of servi… Computing Improvement Program 2.4.10717+ Fix from $1,6002024-08-14 HIGH 7.8 CVE-2024-38163 Windows Update Stack Elevation of Privilege Vulnerability Windows 10 21h2 10.0.19041.3920 / 10.0.20348.2201+ Fix from $1,9502024-08-14 MEDIUM 6.8 CVE-2024-38223 Windows Initial Machine Configuration Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20751 / 10.0.14393.7259+ Fix from $1,6002024-08-13 HIGH 7.8 CVE-2024-38195 Azure CycleCloud Remote Code Execution Vulnerability Azure Cyclecloud 8.6.3+ Fix from $1,9502024-08-13 HIGH 7.8 CVE-2024-38162 Azure Connected Machine Agent Elevation of Privilege Vulnerability Azure Connected Machine Agent 1.44+ Fix from $1,9502024-08-13 MEDIUM 5.5 CVE-2023-31341 Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds w… Uprof 4.1.424 / 4.2.816+ Fix from $1,6002024-08-13 MEDIUM 5.5 CVE-2024-36505 An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an … Fortios 7.0.15 / 7.2.8+ Fix from $1,6002024-08-13 MEDIUM 6.5 CVE-2024-41905 A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access… Sinec Traffic Analyzer 2.0+ Fix from $1,6002024-08-13 MEDIUM 5.4 CVE-2024-41732 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on t… Netweaver Application Server Abap Mitigation only Fix from $1,6002024-08-13 CRITICAL 9.9 CVE-2024-42480 Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC f… Kamaji Patch available Fix from $2,3002024-08-12