Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.4 CVE-2024-39837 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary cha… Mattermost Server 9.5.7+ Fix from $1,6002024-08-01 MEDIUM 6.4 CVE-2024-36492 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing user… Mattermost 9.5.7 / 9.7.6+ Fix from $1,6002024-08-01 CRITICAL 9.8 CVE-2024-38909 Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows a… Elfinder Mitigation only Fix from $2,3002024-07-30 HIGH 7.8 CVE-2024-40812 A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.… Ipados 1.3 / 10.6+ Fix from $1,9502024-07-29 HIGH 7.5 CVE-2024-40786 This issue was addressed through improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Vent… Ipados 13.6.8 / 16.7.9+ Fix from $1,9502024-07-29 CRITICAL 9.1 CVE-2024-28805 An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control. I Mcs Nfv No fix yet Fix from $2,3002024-07-29 MEDIUM 5.4 CVE-2024-6727 A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enable-scale-testing functionalit… Mitigation only Fix from $1,6002024-07-29 HIGH 7.5 CVE-2024-7154 A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file… A3700r Firmware No fix yet Fix from $1,9502024-07-28 CRITICAL 9.8 CVE-2024-40117 Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting… Mitigation only Fix from $2,3002024-07-26 MEDIUM 5.3 CVE-2024-41806 The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the ins… Patch available Fix from $1,6002024-07-25 CRITICAL 9.8 CVE-2024-36535 Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. Meshery Mitigation only Fix from $2,3002024-07-24 HIGH 7.2 CVE-2024-36537 Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tok… Cert Manager Mitigation only Fix from $1,9502024-07-24 HIGH 8.8 CVE-2024-38164 An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to… Groupme Patch available Fix from $1,9502024-07-23 CRITICAL 9.8 CVE-2024-41703 LibreChat through 0.7.4-rc1 has incorrect access control for message updates. Librechat after 0.7.3 Fix from $2,3002024-07-22 HIGH 7.5 CVE-2024-41600 Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login me… Lin Cms Spring Boot after 0.2.1 Fix from $1,9502024-07-19 MEDIUM 6.5 CVE-2024-21169 Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Partners). Supported versions that are affected are 12.2.3-12.2… Marketing after 12.2.13 Fix from $1,6002024-07-16 MEDIUM 6.1 CVE-2024-21150 Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected … Jd Edwards Enterpriseone Tools 9.2.8.2+ Fix from $1,6002024-07-16 HIGH 8.1 CVE-2024-21153 Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The… Process Manufacturing Product Development Mitigation only Fix from $1,9502024-07-16 MEDIUM 5.4 CVE-2024-21132 Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Approvals). Supported versions that are affected are 12.2.3-12… Purchasing after 12.2.13 Fix from $1,6002024-07-16 HIGH 7.5 CVE-2019-16640 An issue was found in upload.php on the Ruijie EG-2000 series gateway. A parameter passed to the class UploadFile is mishandled (%00 and /var/./html … Eg 2000se Firmware Mitigation only Fix from $1,9502024-07-16 HIGH 7.3 CVE-2024-36438 eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card dupli… Mitigation only Fix from $1,9502024-07-15 HIGH 8.8 CVE-2024-6737 The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers… Electronic Official Document Management System 5.0.77+ Fix from $1,9502024-07-15 MEDIUM 5.3 CVE-2024-6738 The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific fil… Tronclass 1.69.61976+ Fix from $1,6002024-07-15 MEDIUM 6.5 CVE-2024-40547 PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace. Publiccms after 4.0.202302.e Fix from $1,6002024-07-12 CRITICAL 9.8 CVE-2024-6385EPSS 6% An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting … GitLab 16.11.6 / 17.0.4+ Fix from $2,3002024-07-11 HIGH 7.0 CVE-2024-34725 In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalat… Android Mitigation only Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31320 In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-38100 Windows File Explorer Elevation of Privilege Vulnerability Windows Server 2016 10.0.14393.7159 / 10.0.17763.6054+ Fix from $1,9502024-07-09 HIGH 7.5 CVE-2024-38061 DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20710 / 10.0.14393.7159+ Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-23663 An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an at… Fortiextender Firmware after 7.4.2 Fix from $1,9502024-07-09