Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2024-25169 An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request. Mezzanine No fix yet Fix from $2,3002024-02-28 MEDIUM 6.5 CVE-2024-1632 Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area. Sitefinity 13.3.7649 / 14.4.8135+ Fix from $1,6002024-02-28 MEDIUM 6.5 CVE-2024-22459 Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. … Elastic Cloud Storage 3.6.2.6 / 3.7.0.7+ Fix from $1,6002024-02-28 MEDIUM 5.3 CVE-2024-0975 The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via t… Wordpress Access Control after 4.0.13 Fix from $1,6002024-02-28 MEDIUM 5.3 CVE-2024-1476 The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… Under Construction \/ Maintenance Mode after 2.6 Fix from $1,6002024-02-28 HIGH 8.8 CVE-2024-25723EPSS 71% ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_o… Zenml 0.42.2 / 0.44.4+ Fix from $1,9502024-02-27 HIGH 7.1 CVE-2024-0551 Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been gran… Anythingllm 1.0.0+ Fix from $1,9502024-02-27 MEDIUM 5.3 CVE-2024-24568 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules insp… Fedora 7.0.3+ Fix from $1,6002024-02-26 HIGH 8.4 CVE-2021-33162 Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated us… Ethernet Controller I225 It Firmware 1.87 / 29.0.1+ Fix from $1,9502024-02-23 MEDIUM 5.3 CVE-2024-1823 A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability is an unknown functionality of… Simple Voting System No fix yet Fix from $1,6002024-02-23 HIGH 8.8 CVE-2024-25251 code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control. Agro School Management System No fix yet Fix from $1,9502024-02-22 HIGH 7.1 CVE-2024-20325 A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data i… Unified Intelligence Center 12.5 / 12.6+ Fix from $1,9502024-02-21 CRITICAL 9.8 CVE-2024-1701 A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown… Php Mysql User Signup Login System No fix yet Fix from $2,3002024-02-21 MEDIUM 5.5 CVE-2023-42945 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Blue… macOS Mitigation only Fix from $1,6002024-02-21 MEDIUM 5.5 CVE-2023-42853 A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may b… macOS 12.7.1 / 13.6.1+ Fix from $1,6002024-02-21 MEDIUM 5.5 CVE-2023-42859 The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be ab… macOS 12.7.1 / 13.6.1+ Fix from $1,6002024-02-21 HIGH 8.6 CVE-2023-42838 An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2… macOS 12.7.2 / 13.6.3+ Fix from $1,9502024-02-21 HIGH 8.8 CVE-2024-1675EPSS 11% Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a… Chrome 122.0.6261.57+ Fix from $1,9502024-02-21 HIGH 8.8 CVE-2023-47422 An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.… Tx9 Firmware No fix yet Fix from $1,9502024-02-20 HIGH 7.4 CVE-2024-22234 In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it di… Spring Security 6.1.7 / 6.2.2+ Fix from $1,9502024-02-20 MEDIUM 6.3 CVE-2022-45320 Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users… Digital Experience Platform 7.2 / 7.4.3.16+ Fix from $1,6002024-02-20 HIGH 8.1 CVE-2023-50257 eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with th… Fast Dds 2.6.7 / 2.10.3+ Fix from $1,9502024-02-19 MEDIUM 5.3 CVE-2024-25980 Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only prov… Moodle 4.1.9 / 4.2.6+ Fix from $1,6002024-02-19 MEDIUM 5.3 CVE-2024-25981 Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only… Moodle 4.1.9 / 4.2.6+ Fix from $1,6002024-02-19 MEDIUM 5.5 CVE-2024-1343 A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to r… Laborofficefree Mitigation only Fix from $1,6002024-02-19 HIGH 7.5 CVE-2023-52375 Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability. Emui No fix yet Fix from $1,9502024-02-18 HIGH 7.7 CVE-2023-52367 Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability an… Emui No fix yet Fix from $1,9502024-02-18 MEDIUM 6.1 CVE-2024-20951 Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are… Customer Interaction History after 12.2.13 Fix from $1,6002024-02-17 HIGH 8.6 CVE-2024-20927 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Mitigation only Fix from $1,9502024-02-17 MEDIUM 6.5 CVE-2024-20929 Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are af… Application Object Library after 12.2.13 Fix from $1,6002024-02-17