Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2023-50181 An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticate… Fortiadc 7.2.5 / 7.4.2+ Fix from $1,6002024-07-09 HIGH 8.6 CVE-2024-39697 phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due … Patch available Fix from $1,9502024-07-09 HIGH 7.7 CVE-2024-39701 Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators.… Directus 10.6.0+ Fix from $1,9502024-07-08 HIGH 8.8 CVE-2024-39943EPSS 39% rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have… Http File Server 0.52.10+ Fix from $1,9502024-07-04 HIGH 7.8 CVE-2024-39934 Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shar… Patch available Fix from $1,9502024-07-04 MEDIUM 6.5 CVE-2024-6428 Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows… Mattermost 9.5.6 / 9.6.3+ Fix from $1,6002024-07-03 MEDIUM 5.3 CVE-2024-36257 Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server… Mattermost 9.5.6+ Fix from $1,6002024-07-03 MEDIUM 5.4 CVE-2024-39361 Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which a… Mattermost 9.5.6 / 9.6.3+ Fix from $1,6002024-07-03 HIGH 8.8 CVE-2024-37905 authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to g… Authentik 2024.2.4 / 2024.4.3+ Fix from $1,9502024-06-28 CRITICAL 9.8 CVE-2024-38371 authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow… Authentik 2024.2.4 / 2024.4.3+ Fix from $2,3002024-06-28 CRITICAL 9.8 CVE-2024-39376 TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their design… Markoni D \(compact\) Firmware 2.0.1+ Fix from $2,3002024-06-27 HIGH 8.8 CVE-2024-5655EPSS 7% An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting … GitLab 16.11.5 / 17.0.3+ Fix from $1,9502024-06-27 MEDIUM 5.3 CVE-2024-2191 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting … GitLab 16.11.5 / 17.0.3+ Fix from $1,6002024-06-27 HIGH 8.2 CVE-2024-37742 Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB k… Mitigation only Fix from $1,9502024-06-25 HIGH 7.4 CVE-2024-21740 Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control. No fix yet Fix from $1,9502024-06-25 CRITICAL 9.8 CVE-2024-21741 GigaDevice GD32E103C8T6 devices have Incorrect Access Control. No fix yet Fix from $2,3002024-06-25 CRITICAL 9.8 CVE-2024-33898 Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows r… Mitigation only Fix from $2,3002024-06-24 HIGH 7.5 CVE-2024-37677 An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacker to obtain sensitive informa… Access Management Specialist No fix yet Fix from $1,9502024-06-24 MEDIUM 5.3 CVE-2024-38873 An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails t… Mitigation only Fix from $1,6002024-06-21 MEDIUM 6.5 CVE-2022-41324 Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to so… Mitigation only Fix from $1,6002024-06-20 HIGH 8.8 CVE-2022-45929 Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their rol… Mitigation only Fix from $1,9502024-06-20 MEDIUM 5.4 CVE-2024-38273 Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access. Moodle 4.1.11 / 4.2.8+ Fix from $1,6002024-06-18 HIGH 8.2 CVE-2022-23829 A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Manage… Mitigation only Fix from $1,9502024-06-18 HIGH 8.5 CVE-2024-5650 DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to int… Mitigation only Fix from $1,9502024-06-17 MEDIUM 5.4 CVE-2024-37884 Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got sh… Nextcloud Server 25.0.13.7 / 26.0.13+ Fix from $1,6002024-06-14 HIGH 8.1 CVE-2024-37882 Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissi… Nextcloud Server 23.0.12.17 / 24.0.12.13+ Fix from $1,9502024-06-14 MEDIUM 6.3 CVE-2024-37312 user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account… User Oidc 5.0.0+ Fix from $1,6002024-06-14 MEDIUM 5.4 CVE-2024-28965 Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabl… Secure Connect Gateway after 5.22.00.18 Fix from $1,6002024-06-13 MEDIUM 5.4 CVE-2024-28966 Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabl… Secure Connect Gateway after 5.22.00.18 Fix from $1,6002024-06-13 MEDIUM 5.4 CVE-2024-28967 Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if … Secure Connect Gateway after 5.22.00.18 Fix from $1,6002024-06-13