Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2024-31846 An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unautho… Embrace No fix yet Fix from $1,9502024-04-19 MEDIUM 6.5 CVE-2024-30107 HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios. Connections Mitigation only Fix from $1,6002024-04-18 HIGH 7.5 CVE-2023-43491 An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A… Smart Reader Firmware No fix yet Fix from $1,9502024-04-17 HIGH 7.5 CVE-2023-45209 An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEM… Smart Reader Firmware No fix yet Fix from $1,9502024-04-17 HIGH 8.8 CVE-2023-45744 A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A speci… Smart Reader Firmware No fix yet Fix from $1,9502024-04-17 HIGH 7.5 CVE-2024-31503 Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CS… Dolibarr Erp\/crm 19.0.1+ Fix from $1,9502024-04-17 HIGH 8.8 CVE-2024-31759 An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function. Publiccms No fix yet Fix from $1,9502024-04-16 HIGH 8.8 CVE-2024-21113 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.16+ Fix from $1,9502024-04-16 HIGH 8.8 CVE-2024-21114 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.16+ Fix from $1,9502024-04-16 HIGH 8.8 CVE-2024-21115 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.16+ Fix from $1,9502024-04-16 MEDIUM 6.7 CVE-2024-21107 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.16+ Fix from $1,6002024-04-16 HIGH 7.3 CVE-2024-21110 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.16+ Fix from $1,9502024-04-16 HIGH 8.8 CVE-2024-21112 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.16+ Fix from $1,9502024-04-16 HIGH 7.8 CVE-2024-21103 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.16+ Fix from $1,9502024-04-16 MEDIUM 6.5 CVE-2024-21091 Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The supported v… Agile Product Lifecycle Management For Process Mitigation only Fix from $1,6002024-04-16 MEDIUM 5.8 CVE-2024-21084 Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Service Gateway). Supported versions that are affected are 7.0.0.0.… Bi Publisher Mitigation only Fix from $1,6002024-04-16 HIGH 7.5 CVE-2024-21074 Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Finance LOV). Supported versions that are affected are 1… Trade Management after 12.2.13 Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-21076 Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Offer LOV). Supported versions that are affected are 12.… Trade Management after 12.2.13 Fix from $1,9502024-04-16 HIGH 8.8 CVE-2024-21067 Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Host Management). The supported versi… Enterprise Manager Base Platform Mitigation only Fix from $1,9502024-04-16 CRITICAL 9.1 CVE-2024-21071 Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affect… Workflow after 12.2.13 Fix from $2,3002024-04-16 HIGH 7.5 CVE-2024-24485 An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command. Ds 600 Firmware Mitigation only Fix from $1,9502024-04-15 CRITICAL 9.1 CVE-2024-24486 An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command. Ds 600 Firmware Mitigation only Fix from $2,3002024-04-15 MEDIUM 6.8 CVE-2024-24487 An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using t… Ds 600 Firmware Mitigation only Fix from $1,6002024-04-15 HIGH 7.5 CVE-2024-29842 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_A… Evolution after 2.04.560 Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-29843 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, … Evolution after 2.04.560 Fix from $1,9502024-04-15 HIGH 8.8 CVE-2024-29837 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attack… Evolution after 2.04.560 Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-29839 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_C… Evolution after 2.04.560 Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-29840 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_P… Evolution after 2.04.560 Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-29841 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_K… Evolution after 2.04.560 Fix from $1,9502024-04-15 CRITICAL 9.8 CVE-2024-29836 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthent… Evolution after 2.04.560 Fix from $2,3002024-04-15