Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2024-3765 A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, AHB7004T-MHV2, AHB8032F-LME an… No fix yet Fix from $2,3002024-04-14 HIGH 8.8 CVE-2024-25852EPSS 17% Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control functio… Re7000 Firmware No fix yet Fix from $1,9502024-04-11 HIGH 7.5 CVE-2024-2217 gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is pr… Chuanhuchatgpt Patch available Fix from $1,9502024-04-10 MEDIUM 5.4 CVE-2024-2731 Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages that expose sensitive informa… Mitigation only Fix from $1,6002024-04-10 HIGH 7.5 CVE-2024-1308 The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… Mitigation only Fix from $1,9502024-04-09 MEDIUM 5.3 CVE-2024-0899 The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress i… Mitigation only Fix from $1,6002024-04-09 MEDIUM 5.3 CVE-2024-0626 The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… Mitigation only Fix from $1,6002024-04-09 CRITICAL 9.0 CVE-2024-29990EPSS 18% Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability Azure Kubernetes Service Confidential Containers 0.3.4+ Fix from $2,3002024-04-09 HIGH 8.8 CVE-2024-29993 Azure CycleCloud Elevation of Privilege Vulnerability Azure Cyclecloud No fix yet Fix from $1,9502024-04-09 HIGH 7.2 CVE-2024-29054 Microsoft Defender for IoT Elevation of Privilege Vulnerability Defender For Iot 24.1.3+ Fix from $1,9502024-04-09 HIGH 7.2 CVE-2024-29055 Microsoft Defender for IoT Elevation of Privilege Vulnerability Defender For Iot 24.1.3+ Fix from $1,9502024-04-09 MEDIUM 6.2 CVE-2024-28917 Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability Azure Arc Extension Microsoft.azstackhci.operator 0.3.0-preview / 1.0.2620-162+ Fix from $1,6002024-04-09 MEDIUM 6.7 CVE-2024-26234 Proxy Driver Spoofing Vulnerability Windows 10 1507 10.0.10240.20596 / 10.0.14393.6897+ Fix from $1,6002024-04-09 MEDIUM 6.5 CVE-2024-21424 Azure Compute Gallery Elevation of Privilege Vulnerability Azure Compute Gallery No fix yet Fix from $1,6002024-04-09 MEDIUM 6.5 CVE-2024-31805 TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setT… Ex200 Firmware No fix yet Fix from $1,6002024-04-08 HIGH 7.5 CVE-2024-27895 Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality. Harmonyos No fix yet Fix from $1,9502024-04-08 HIGH 7.5 CVE-2023-52537 Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect avai… Emui No fix yet Fix from $1,9502024-04-08 HIGH 7.5 CVE-2024-30418 Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect… Emui Mitigation only Fix from $1,9502024-04-07 MEDIUM 6.5 CVE-2024-2447 Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain ty… Mattermost Server 8.1.11 / 9.3.3+ Fix from $1,6002024-04-05 MEDIUM 5.9 CVE-2024-31207 Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.d… Patch available Fix from $1,6002024-04-04 MEDIUM 5.3 CVE-2023-36644 Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail… Tradepro No fix yet Fix from $1,6002024-04-04 MEDIUM 5.3 CVE-2023-36643 Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in cu… Tradepro No fix yet Fix from $1,6002024-04-04 MEDIUM 5.3 CVE-2024-1418 The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2 via the REST … Mitigation only Fix from $1,6002024-04-04 MEDIUM 6.5 CVE-2024-3270 A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeat… Thingsboard after 3.6.2 Fix from $1,6002024-04-03 HIGH 7.5 CVE-2024-27605 Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system. Alldata Mitigation only Fix from $1,9502024-04-02 CRITICAL 9.1 CVE-2024-27602 Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v… Alldata Mitigation only Fix from $2,3002024-04-02 HIGH 7.2 CVE-2024-28405 SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin … Semcms No fix yet Fix from $1,9502024-03-29 HIGH 8.2 CVE-2024-28960 An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared m… Fedora 2.28.8 / 3.6.0+ Fix from $1,9502024-03-29 MEDIUM 6.0 CVE-2024-28016 Improper Access Controlvulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, … Aterm Wg1800hp4 Firmware Mitigation only Fix from $1,6002024-03-28 MEDIUM 6.5 CVE-2024-25962 Dell InsightIQ, version 5.0, contains an improper access control vulnerability. A remote low privileged attacker could potentially exploit this vulne… Insightiq Mitigation only Fix from $1,6002024-03-27