Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.9 CVE-2024-32045 Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linki… Mattermost Server 8.1.13 / 9.5.4+ Fix from $1,6002024-05-26 MEDIUM 6.3 CVE-2024-31859 Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a pl… Mattermost Server 8.1.13 / 9.5.4+ Fix from $1,6002024-05-26 CRITICAL 9.8 CVE-2024-35396 TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attac… Cp900l Firmware Mitigation only Fix from $2,3002024-05-24 MEDIUM 5.9 CVE-2024-35222 Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications can access the Tauri IPC endp… Mitigation only Fix from $1,6002024-05-23 CRITICAL 9.8 CVE-2024-5168 Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthent… Mitigation only Fix from $2,3002024-05-23 HIGH 8.1 CVE-2024-26139 OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack of certain… Opencti after 5.12.31 Fix from $1,9502024-05-23 MEDIUM 6.7 CVE-2024-22026 A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitra… Endpoint Manager Mobile 12.1.0.0+ Fix from $1,6002024-05-22 HIGH 7.8 CVE-2024-27264 IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici… I Mitigation only Fix from $1,9502024-05-22 MEDIUM 5.8 CVE-2024-20261 A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could all… Secure Firewall Threat Defense Mitigation only Fix from $1,6002024-05-22 HIGH 8.8 CVE-2024-33227 An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execute arbitrary code via sending … Mitigation only Fix from $1,9502024-05-22 MEDIUM 5.0 CVE-2024-0451 The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback f… Wpbot 5.3.6+ Fix from $1,6002024-05-22 HIGH 7.7 CVE-2024-0452 The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_ca… Wpbot 5.3.6+ Fix from $1,9502024-05-22 HIGH 7.7 CVE-2024-0453 The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_ca… Wpbot 5.3.6+ Fix from $1,9502024-05-22 HIGH 8.8 CVE-2023-52801 In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In iopt_… Linux Kernel 6.5.13 / 6.6.3+ Fix from $1,9502024-05-21 HIGH 7.5 CVE-2024-4988 The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to the risk of private file leakag… Mitigation only Fix from $1,9502024-05-21 CRITICAL 9.8 CVE-2024-36080 Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-… Mitigation only Fix from $2,3002024-05-19 MEDIUM 6.7 CVE-2024-21828 Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to pot… Mitigation only Fix from $1,6002024-05-16 MEDIUM 5.5 CVE-2023-47859 Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially… Mitigation only Fix from $1,6002024-05-16 HIGH 7.8 CVE-2023-43748 Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enabl… Graphics Performance Analyzers Framework 2023.3+ Fix from $1,9502024-05-16 HIGH 7.8 CVE-2023-45217 Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation o… Power Gadget 3.6.0+ Fix from $1,9502024-05-16 HIGH 8.8 CVE-2023-40070 Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalatio… Power Gadget Mitigation only Fix from $1,9502024-05-16 HIGH 7.8 CVE-2023-40071 Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalati… Graphics Performance Analyzers 2023.3+ Fix from $1,9502024-05-16 HIGH 7.8 CVE-2022-37341 Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user t… Ethernet Controller I225 It Firmware 1.87 / 29.0.1+ Fix from $1,9502024-05-16 HIGH 7.0 CVE-2022-37410 Improper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user to potentially enable escalat… Mitigation only Fix from $1,9502024-05-16 MEDIUM 5.4 CVE-2024-4263 A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an expe… Mlflow 2.12.1+ Fix from $1,6002024-05-16 MEDIUM 6.5 CVE-2024-28087 In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription … Mitigation only Fix from $1,6002024-05-15 HIGH 7.8 CVE-2024-34099 Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrar… Acrobat Dc 20.005.30635 / 20.005.30636+ Fix from $1,9502024-05-15 MEDIUM 5.5 CVE-2024-30059 Microsoft Intune for Android Mobile Application Management Tampering Vulnerability Intune Mobile Application Management 5.0.6215.0+ Fix from $1,6002024-05-14 MEDIUM 6.5 CVE-2024-33647 A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in the affected application lacks … Mitigation only Fix from $1,6002024-05-14 MEDIUM 5.9 CVE-2024-2749 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings,… Vikbooking Hotel Booking Engine \& Pms 1.6.8+ Fix from $1,6002024-05-14