Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2024-28120 codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check … Codeium No fix yet Fix from $1,9502024-03-11 HIGH 8.8 CVE-2024-25501 An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter. Winmail after 7.1 Fix from $1,9502024-03-09 CRITICAL 9.8 CVE-2024-2281 A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been declared as critical. This vulnerability affects unknown code… Automated Mess Management System Mitigation only Fix from $2,3002024-03-08 MEDIUM 5.5 CVE-2024-23266 The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be ab… macOS 12.7.4 / 13.6.5+ Fix from $1,6002024-03-08 MEDIUM 5.5 CVE-2024-23267 The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be ab… macOS 12.7.4 / 13.6.5+ Fix from $1,6002024-03-08 HIGH 8.6 CVE-2024-0258 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A… Ipad Os 10.4 / 14.4+ Fix from $1,9502024-03-08 HIGH 7.8 CVE-2024-28115 FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local priv… Freertos 10.6.2+ Fix from $1,9502024-03-07 CRITICAL 9.1 CVE-2023-51786 An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive inf… Mitigation only Fix from $2,3002024-03-07 CRITICAL 9.8 CVE-2023-38945 Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_p… Re160 Firmware No fix yet Fix from $2,3002024-03-06 HIGH 8.8 CVE-2023-38946 An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access control and gain complete access … Re160 Firmware No fix yet Fix from $1,9502024-03-06 HIGH 8.8 CVE-2023-43318 TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' value… Tl Sg2210p Firmware Mitigation only Fix from $1,9502024-03-06 MEDIUM 5.3 CVE-2024-1478 The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST AP… Maintenance Mode 3.0.2+ Fix from $1,6002024-03-05 MEDIUM 5.3 CVE-2024-1088 The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… Password Protected Store For Woocommerce 2.3+ Fix from $1,6002024-03-05 HIGH 7.2 CVE-2024-0795 If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from… Anythingllm 1.0.0+ Fix from $1,9502024-03-02 CRITICAL 9.8 CVE-2023-49543 Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions withou… Book Store Management System No fix yet Fix from $2,3002024-03-01 HIGH 7.5 CVE-2023-49545 A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application witho… Customer Support System No fix yet Fix from $1,9502024-03-01 CRITICAL 9.4 CVE-2024-21767 A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request. No fix yet Fix from $2,3002024-03-01 HIGH 8.8 CVE-2024-27497EPSS 27% Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file. E2000 Firmware No fix yet Fix from $1,9502024-03-01 CRITICAL 9.8 CVE-2024-25830EPSS 24% F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker… Datacube3 Firmware No fix yet Fix from $2,3002024-02-29 MEDIUM 5.8 CVE-2024-20291 A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalon… Nx Os Mitigation only Fix from $1,6002024-02-29 MEDIUM 5.3 CVE-2024-1472 The WP Maintenance plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.1.6 via the REST API. This make… Wp Maintenance 6.1.7+ Fix from $1,6002024-02-29 MEDIUM 5.3 CVE-2024-1475 The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via… Coming Soon Maintenance Mode 1.0.6+ Fix from $1,6002024-02-29 MEDIUM 5.3 CVE-2024-1492 The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta … Woo Czech 4.0.9+ Fix from $1,6002024-02-29 MEDIUM 5.3 CVE-2024-1294 The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions… Sunshine Photo Cart 3.1+ Fix from $1,6002024-02-29 MEDIUM 5.3 CVE-2024-1044 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the… Customer Reviews For Woocommerce 5.39.0+ Fix from $1,6002024-02-29 MEDIUM 5.3 CVE-2024-0978 The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.14 via the REST AP… My Private Site 3.1.0+ Fix from $1,6002024-02-29 HIGH 8.4 CVE-2023-51774 The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE … Json Jwt No fix yet Fix from $1,9502024-02-29 CRITICAL 9.8 CVE-2023-49930 An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted. Couchbase Server 7.2.4+ Fix from $2,3002024-02-29 CRITICAL 9.8 CVE-2023-49931 An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted. Couchbase Server 7.2.4+ Fix from $2,3002024-02-29 CRITICAL 9.8 CVE-2022-34270 An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager. Worldserver 11.7.3+ Fix from $2,3002024-02-29