Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.5 CVE-2024-27841 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disc… Ipados 14.5 / 17.5+ Fix from $1,6002024-05-14 HIGH 7.5 CVE-2024-27790 Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. Thi… Filemaker Server 20.3.2+ Fix from $1,9502024-05-14 HIGH 8.8 CVE-2022-32507 An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged … Mitigation only Fix from $1,9502024-05-14 HIGH 7.8 CVE-2024-0025 In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local esc… Android Patch available Fix from $1,9502024-05-07 HIGH 7.5 CVE-2024-29207 An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. Affected Prod… Mitigation only Fix from $1,9502024-05-07 HIGH 7.8 CVE-2024-23351 Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions. Fastconnect 6200 Firmware Patch available Fix from $1,9502024-05-06 MEDIUM 6.4 CVE-2024-34068 Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the prev… Wings 1.11.2+ Fix from $1,6002024-05-03 MEDIUM 6.8 CVE-2024-34404 A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, onl… Mitigation only Fix from $1,6002024-05-03 HIGH 8.4 CVE-2024-33396 An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component. Mitigation only Fix from $1,9502024-05-02 MEDIUM 5.3 CVE-2024-1678 The Subway – Private Site Option plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via… Mitigation only Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-1584 The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of… Analytify Google Analytics Dashboard 5.2.4+ Fix from $1,6002024-05-02 CRITICAL 9.1 CVE-2024-31967 A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit t… Mitigation only Fix from $2,3002024-05-02 HIGH 7.5 CVE-2024-31964 A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit t… Mitigation only Fix from $1,9502024-05-02 MEDIUM 6.2 CVE-2024-33393 An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token compo… Mitigation only Fix from $1,6002024-05-01 MEDIUM 5.3 CVE-2024-22830 Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control when handling system resources.… Mitigation only Fix from $1,6002024-05-01 MEDIUM 6.5 CVE-2024-28978 Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged remote attacker could potenti… Openmanage Enterprise Mitigation only Fix from $1,6002024-05-01 MEDIUM 5.5 CVE-2024-3746 The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, … Scadapro Server Mitigation only Fix from $1,6002024-04-30 CRITICAL 9.8 CVE-2023-49473 Shenzhen JF6000 Cloud Media Collaboration Processing Platform firmware version V1.2.0 and software version V2.0.0 build 6245 is vulnerable to Incorre… Mitigation only Fix from $2,3002024-04-30 HIGH 7.6 CVE-2024-4225 Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can … Mitigation only Fix from $1,9502024-04-30 MEDIUM 5.1 CVE-2024-33260 Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at jerry-core/parser/js/js-parser-… Jerryscript No fix yet Fix from $1,6002024-04-26 HIGH 7.8 CVE-2024-33673 An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search … Backup Exec 23.0+ Fix from $1,9502024-04-26 HIGH 8.6 CVE-2024-33666 An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via… Zammad 6.3.0+ Fix from $1,9502024-04-26 MEDIUM 6.5 CVE-2024-23271 A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS… Safari 10.3 / 14.3+ Fix from $1,6002024-04-24 HIGH 8.4 CVE-2023-38297 An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufacturers. Certain software buil… Mitigation only Fix from $1,9502024-04-22 HIGH 8.8 CVE-2023-38298 Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by any loc… Mitigation only Fix from $1,9502024-04-22 HIGH 8.0 CVE-2023-38296 Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any local app on th… Mitigation only Fix from $1,9502024-04-22 CRITICAL 9.8 CVE-2024-27348 KEVEPSS 99% RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & … Hugegraph 1.3.0+ Fix from $2,3002024-04-22 MEDIUM 6.5 CVE-2024-22807 An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the flash memory, causing the machi… Pathpilot Controller Mitigation only Fix from $1,6002024-04-22 HIGH 8.2 CVE-2024-22811 An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communicatio… Pathpilot Controller Mitigation only Fix from $1,9502024-04-22 CRITICAL 9.8 CVE-2024-32418 An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component. Flusity No fix yet Fix from $2,3002024-04-22