Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2024-25736 An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request. Apollo Vx20 Firmware 1.3.58+ Fix from $1,9502024-03-27 HIGH 8.8 CVE-2023-50702 Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have… Mitigation only Fix from $1,9502024-03-26 CRITICAL 9.1 CVE-2024-29866 Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate… Seq 2023.4.11151 / 2024.1.11146+ Fix from $2,3002024-03-21 MEDIUM 6.5 CVE-2024-25811 An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information. Dreamer Cms No fix yet Fix from $1,6002024-03-21 HIGH 8.8 CVE-2023-49978 Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for… Customer Support System No fix yet Fix from $1,9502024-03-21 CRITICAL 9.1 CVE-2020-26942 An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminP… Axigen Mail Server 10.3.1.27 / 10.3.3.1+ Fix from $2,3002024-03-21 MEDIUM 5.3 CVE-2024-1473 The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.9… Coming Soon \& Maintenance Mode after 1.0.99 Fix from $1,6002024-03-20 MEDIUM 6.5 CVE-2024-1144 Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an unauthentica… Alma Blog after 2.1.10 Fix from $1,6002024-03-19 HIGH 7.4 CVE-2024-20767 KEVEPSS 99% ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system r… Coldfusion Mitigation only Fix from $1,9502024-03-18 CRITICAL 9.1 CVE-2021-47155 The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allo… Mitigation only Fix from $2,3002024-03-18 HIGH 7.5 CVE-2022-47037 Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials. Tg Firmware 2.1.1+ Fix from $1,9502024-03-18 CRITICAL 9.8 CVE-2022-47036 Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash.… Mitigation only Fix from $2,3002024-03-18 MEDIUM 6.5 CVE-2024-2481 A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected is an unknown function of the … Hostel Management System No fix yet Fix from $1,6002024-03-15 CRITICAL 9.8 CVE-2024-28390 An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sens… Ultimateimagetool 2.2.01+ Fix from $2,3002024-03-14 MEDIUM 5.8 CVE-2024-20322 A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an… Ios Xr Mitigation only Fix from $1,6002024-03-13 MEDIUM 5.8 CVE-2024-20315 A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unaut… Mitigation only Fix from $1,6002024-03-13 MEDIUM 6.5 CVE-2024-1668 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and inc… Avada 7.11.6+ Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-1462 The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. T… Maintenance Page 1.0.9+ Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-0687 The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Exposure in all versions up to,… Restrict User Access 2.6+ Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-0631 The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_dui… Duitku Payment Gateway after 2.11.4 Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-0377 The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… Lifterlms 7.5.2+ Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2023-6785 The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and includ… Download Manager 3.2.85+ Fix from $1,6002024-03-13 HIGH 8.0 CVE-2024-28338 A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie. A8000ru Firmware No fix yet Fix from $1,9502024-03-12 MEDIUM 6.6 CVE-2024-26201 Microsoft Intune Linux Agent Elevation of Privilege Vulnerability Intune Company Portal 1.2402.12+ Fix from $1,6002024-03-12 HIGH 7.3 CVE-2024-26203 Azure Data Studio Elevation of Privilege Vulnerability Azure Data Studio 1.48.0+ Fix from $1,9502024-03-12 HIGH 7.8 CVE-2024-21436 Windows Installer Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20526 / 10.0.14393.6796+ Fix from $1,9502024-03-12 HIGH 7.8 CVE-2024-21418 Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability Software For Open Networking In The Cloud 20181130.106 / 20191130.89+ Fix from $1,9502024-03-12 CRITICAL 9.8 CVE-2023-36554 A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.… Fortimanager after 7.2.3 Fix from $2,3002024-03-12 CRITICAL 9.8 CVE-2022-32257 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that la… Sinema Remote Connect Server 3.2+ Fix from $2,3002024-03-12 HIGH 7.8 CVE-2024-21805 Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnera… Skysea Client View 19.300.09h+ Fix from $1,9502024-03-12