Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2024-0212 The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged ac… Cloudflare 4.12.3+ Fix from $1,6002024-01-29 HIGH 7.2 CVE-2024-20263 A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and B… Cbs250 8t D Firmware 2.5.9.54 / 3.4.0.17+ Fix from $1,9502024-01-26 MEDIUM 5.5 CVE-2023-40528 This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS 17, macOS Ve… Ipados 10.0 / 13.6.4+ Fix from $1,6002024-01-23 MEDIUM 6.5 CVE-2024-23675 In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST… Cloud 9.0.8 / 9.1.3+ Fix from $1,6002024-01-22 HIGH 8.2 CVE-2024-23681 Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or S… Artemis Java Test Sandbox 1.11.2+ Fix from $1,9502024-01-19 HIGH 7.5 CVE-2024-23331 Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems usi… Vite 2.9.17 / 3.2.8+ Fix from $1,9502024-01-19 MEDIUM 5.5 CVE-2023-32544 Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may … Nuc P14e Laptop Element 1.1.45+ Fix from $1,6002024-01-19 HIGH 7.5 CVE-2023-47034 A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors. Uniswapfrontrunbot No fix yet Fix from $1,9502024-01-19 CRITICAL 9.8 CVE-2024-0712 A vulnerability was found in Byzoro Smart S150 Management Platform V31R02B15. It has been classified as critical. Affected is an unknown function of … Smart S150 Firmware No fix yet Fix from $2,3002024-01-19 CRITICAL 9.8 CVE-2024-22415 jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Serve… Language Server Protocol Integration 2.2.2+ Fix from $2,3002024-01-18 MEDIUM 6.7 CVE-2023-20260 A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, loc… Evolved Programmable Network Manager 3.10.4 / 7.1.1+ Fix from $1,6002024-01-17 CRITICAL 9.8 CVE-2024-0642 Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the app… Live Encoder Mitigation only Fix from $2,3002024-01-17 MEDIUM 6.5 CVE-2024-22407 Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations fo… Shopware 6.5.7.4+ Fix from $1,6002024-01-16 MEDIUM 5.5 CVE-2024-20969 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8… MySQL after 8.2.0 Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2024-20948 Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected … Knowledge Management after 12.2.13 Fix from $1,6002024-01-16 HIGH 7.4 CVE-2024-20952 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp… Openjdk 11.0.24 / 17.0.10+ Fix from $1,9502024-01-16 MEDIUM 6.1 CVE-2024-20936 Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected a… One To One Fulfillment after 12.2.13 Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2024-20938 Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: ECC). Supported versions that are affected are 12.2.3-12.2.13. Eas… Istore after 12.2.13 Fix from $1,6002024-01-16 MEDIUM 5.9 CVE-2024-20926 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Sup… Debian Linux Patch available Fix from $1,6002024-01-16 HIGH 7.5 CVE-2024-20932 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp… Graalvm Patch available Fix from $1,9502024-01-16 HIGH 8.3 CVE-2024-20916 Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported vers… Enterprise Manager Patch available Fix from $1,9502024-01-16 HIGH 7.4 CVE-2024-20918 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo… Debian Linux Patch available Fix from $1,9502024-01-16 HIGH 7.4 CVE-2023-21901 Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: I… Financial Services Analytical Applications Infrastructure Patch available Fix from $1,9502024-01-16 CRITICAL 9.1 CVE-2024-0570 A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi… N350rt Firmware Mitigation only Fix from $2,3002024-01-16 HIGH 7.5 CVE-2023-52099 Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service c… Emui No fix yet Fix from $1,9502024-01-16 HIGH 7.5 CVE-2023-52105 The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,9502024-01-16 HIGH 7.5 CVE-2023-52114 Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity. Emui No fix yet Fix from $1,9502024-01-16 HIGH 8.8 CVE-2024-22209 Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call e… Edx Platform 2024-01-12+ Fix from $1,9502024-01-13 HIGH 7.5 CVE-2023-51070 An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensiti… Archive Storage Manager No fix yet Fix from $1,9502024-01-13 HIGH 7.5 CVE-2023-51065 Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and… Archive Storage Manager No fix yet Fix from $1,9502024-01-13