Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.4 CVE-2024-28968 Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection setting… Secure Connect Gateway after 5.22.00.18 Fix from $1,6002024-06-13 HIGH 7.5 CVE-2024-34112EPSS 24% ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system r… Coldfusion Mitigation only Fix from $1,9502024-06-13 CRITICAL 9.8 CVE-2024-34107 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in… Commerce after 1.4.0 Fix from $2,3002024-06-13 CRITICAL 9.8 CVE-2024-26029 Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature… Experience Manager 6.5.21 / 2024.5+ Fix from $2,3002024-06-13 MEDIUM 6.5 CVE-2024-5840 Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML pag… Chrome 126.0.6478.54+ Fix from $1,6002024-06-11 MEDIUM 6.7 CVE-2024-29060 Visual Studio Elevation of Privilege Vulnerability Visual Studio 2017 15.9.63 / 16.11.37+ Fix from $1,6002024-06-11 MEDIUM 5.3 CVE-2024-5687 If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. … Firefox 127.0+ Fix from $1,6002024-06-11 HIGH 7.8 CVE-2024-37289 An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Pl… Apex One 14.0.0.12980 / 14.0.13139+ Fix from $1,9502024-06-10 HIGH 8.8 CVE-2024-27855 The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, macOS… Ipados 13.6.7 / 14.5+ Fix from $1,9502024-06-10 MEDIUM 5.5 CVE-2024-27792 This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user… macOS 14.4+ Fix from $1,6002024-06-10 HIGH 7.8 CVE-2022-48683 An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13. An app may be able to break out of its s… macOS 13.0+ Fix from $1,9502024-06-10 HIGH 7.5 CVE-2024-37568 lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verific… Authlib 1.3.1+ Fix from $1,9502024-06-09 HIGH 8.8 CVE-2024-30481 Broken Access Control vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.0.0. Jch Optimize 4.0.1+ Fix from $1,9502024-06-09 CRITICAL 9.8 CVE-2024-22074 Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.12… Dynamsoft Service 1.3.3212 / 1.4.3212+ Fix from $2,3002024-06-06 MEDIUM 6.3 CVE-2024-36399 Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php functio… Kanboard 1.2.37+ Fix from $1,6002024-06-06 MEDIUM 5.3 CVE-2024-0972 The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the … Buddypress Members Only after 3.3.5 Fix from $1,6002024-06-06 HIGH 8.1 CVE-2023-6966 The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capabil… The Moneytizer 10.0.1+ Fix from $1,9502024-06-06 MEDIUM 5.4 CVE-2023-6968 The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.6.3. This is due to missi… The Moneytizer 10.0.1+ Fix from $1,6002024-06-06 HIGH 7.5 CVE-2024-28818 An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exy… Exynos 980 Firmware Mitigation only Fix from $1,9502024-06-05 HIGH 7.5 CVE-2024-2019 The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to lack of a def… Mitigation only Fix from $1,9502024-06-04 HIGH 7.8 CVE-2024-23360 Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers. Fastconnect 6700 Firmware No fix yet Fix from $1,9502024-06-03 HIGH 8.1 CVE-2024-35433 ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create… Zkbio Cvsecurity No fix yet Fix from $1,9502024-05-30 MEDIUM 5.3 CVE-2024-0434 The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due t… Mitigation only Fix from $1,6002024-05-29 MEDIUM 5.3 CVE-2023-43847 Incorrect access control in the outlet control function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to cont… Pe6208 Firmware 2.4.239+ Fix from $1,6002024-05-28 HIGH 8.0 CVE-2023-43848 Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to… Pe6208 Firmware 2.4.239+ Fix from $1,9502024-05-28 MEDIUM 6.5 CVE-2023-43849 Incorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to submit… Pe6208 Firmware 2.4.239+ Fix from $1,6002024-05-28 CRITICAL 9.1 CVE-2024-22187 A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.… P3 550e Firmware No fix yet Fix from $2,3002024-05-28 HIGH 7.5 CVE-2024-23315 A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550E 1.2.10.9… P3 550e Firmware No fix yet Fix from $1,9502024-05-28 HIGH 7.8 CVE-2023-52711 Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place … Curiem Wfg9b Firmware Mitigation only Fix from $1,9502024-05-28 HIGH 7.8 CVE-2023-52712 Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place … Curiem Wfg9b Firmware Mitigation only Fix from $1,9502024-05-28