Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.1 CVE-2023-20587 Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution. Mitigation only Fix from $1,9502024-02-13 MEDIUM 6.0 CVE-2023-31346 Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests. Epyc 7773x Firmware Mitigation only Fix from $1,6002024-02-13 HIGH 8.8 CVE-2024-24751 sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access… Event Management And Registration Patch available Fix from $1,9502024-02-13 CRITICAL 9.8 CVE-2024-21401 Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability Entra Jira Sso Plugin 1.1.2+ Fix from $2,3002024-02-13 CRITICAL 9.0 CVE-2024-21376 Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability Azure Kubernetes Service Patch available Fix from $2,3002024-02-13 CRITICAL 9.3 CVE-2024-21364 Microsoft Azure Site Recovery Elevation of Privilege Vulnerability Azure Site Recovery Patch available Fix from $2,3002024-02-13 MEDIUM 5.7 CVE-2024-20695 Skype for Business Information Disclosure Vulnerability Skype For Business Server Patch available Fix from $1,6002024-02-13 HIGH 8.8 CVE-2024-25677 In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resource… Min Mitigation only Fix from $1,9502024-02-09 HIGH 8.8 CVE-2024-24830 OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability … Openobserve 0.8.0+ Fix from $1,9502024-02-08 MEDIUM 6.5 CVE-2024-25106 OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulne… Openobserve 0.8.0+ Fix from $1,6002024-02-08 CRITICAL 9.8 CVE-2024-24496EPSS 20% An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-t… Daily Habit Tracker No fix yet Fix from $2,3002024-02-08 MEDIUM 5.3 CVE-2024-0965 The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 … Simple Page Access Restriction after 1.0.21 Fix from $1,6002024-02-08 HIGH 8.8 CVE-2024-24824EPSS 34% Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded… Graylog 5.1.11 / 5.2.4+ Fix from $1,9502024-02-07 MEDIUM 5.9 CVE-2024-24771 Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authe… Open Forms 2.2.9 / 2.3.7+ Fix from $1,6002024-02-07 MEDIUM 6.5 CVE-2024-23446 An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (F… Kibana 8.12.1+ Fix from $1,6002024-02-07 MEDIUM 6.5 CVE-2024-23447 An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allo… Network Drive Connector 8.12.1+ Fix from $1,6002024-02-07 HIGH 7.8 CVE-2023-32479 Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation v… Encryption 11.9.0+ Fix from $1,9502024-02-06 HIGH 7.8 CVE-2023-43517 Memory corruption in Automotive Multimedia due to improper access control in HAB. Qam8255p Firmware No fix yet Fix from $1,9502024-02-06 MEDIUM 5.3 CVE-2024-0969 The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This… Armember after 4.0.24 Fix from $1,6002024-02-05 HIGH 7.5 CVE-2024-0324 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized mod… Profile Builder after 3.10.8 Fix from $1,9502024-02-05 MEDIUM 6.5 CVE-2024-22202 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacke… Phpmyfaq 3.2.5+ Fix from $1,6002024-02-05 MEDIUM 6.5 CVE-2021-46903 An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. An admin can … Lantime Firmware 6.24.029 / 7.04.008+ Fix from $1,6002024-02-04 HIGH 7.5 CVE-2023-44031 Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in… Reprise License Manager 16.0+ Fix from $1,9502024-02-03 HIGH 8.8 CVE-2023-38263 IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM … Soar Qradar Plugin App 5.0.3+ Fix from $1,9502024-02-02 CRITICAL 9.8 CVE-2023-32333 IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 2550… Maximo Asset Management Patch available Fix from $2,3002024-02-02 HIGH 8.8 CVE-2023-47867 MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and comp… Feverwarn Firmware Mitigation only Fix from $1,9502024-02-01 CRITICAL 9.8 CVE-2024-1114 A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function dlfile of the file /applicat… Openbi after 1.0.8 Fix from $2,3002024-01-31 MEDIUM 5.3 CVE-2024-24566 Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is pass… Lobe Chat 0.122.4+ Fix from $1,6002024-01-31 CRITICAL 9.8 CVE-2024-21653 The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). … Vantage6 4.2.0+ Fix from $2,3002024-01-30 HIGH 8.8 CVE-2024-1011 A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability affects unknown code of the … Employee Management System No fix yet Fix from $1,9502024-01-29