Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2024-22206 Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth(… Javascript 4.29.3+ Fix from $2,3002024-01-12 HIGH 7.5 CVE-2024-21589 An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated network-based atta… Paragon Active Assurance Control Center Mitigation only Fix from $1,9502024-01-12 MEDIUM 6.3 CVE-2024-20675 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Edge Chromium 120.0.2210.133+ Fix from $1,6002024-01-11 CRITICAL 9.8 CVE-2024-0415 A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the fil… Dsmall after 6.1.0 Fix from $2,3002024-01-11 CRITICAL 9.8 CVE-2024-0413 A vulnerability was found in DeShang DSKMS up to 3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file publ… Dskms after 3.1.2 Fix from $2,3002024-01-11 CRITICAL 9.8 CVE-2024-0414 A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install… Dscms after 3.1.2 Fix from $2,3002024-01-11 HIGH 7.5 CVE-2024-0411 A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/insta… Dsmall after 6.1.0 Fix from $1,9502024-01-11 CRITICAL 9.8 CVE-2024-0412 A vulnerability was found in DeShang DSShop up to 3.1.0. It has been declared as problematic. This vulnerability affects unknown code of the file pub… Dsshop Mitigation only Fix from $2,3002024-01-11 HIGH 8.8 CVE-2023-50159 In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This i… Scalefusion No fix yet Fix from $1,9502024-01-11 MEDIUM 6.8 CVE-2023-51751 ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launch… Scalefusion Mitigation only Fix from $1,6002024-01-11 MEDIUM 5.3 CVE-2023-6582 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via… Elements Kit Elementor Addons 3.0.4+ Fix from $1,6002024-01-11 MEDIUM 6.5 CVE-2024-21666 The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing auto… Customer Management Framework 4.0.6+ Fix from $1,6002024-01-11 MEDIUM 6.5 CVE-2024-21667 pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorize… Customer Management Framework 4.0.6+ Fix from $1,6002024-01-11 MEDIUM 5.5 CVE-2022-42816 A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of … macOS 13.0+ Fix from $1,6002024-01-10 HIGH 8.8 CVE-2023-46712 A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to es… Fortiportal after 7.2.1 Fix from $1,9502024-01-10 CRITICAL 9.1 CVE-2022-46025 Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system inform… N200re V5 Firmware Patch available Fix from $2,3002024-01-10 MEDIUM 5.3 CVE-2023-41603 D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any servi… R15 Firmware after 1.08.02 Fix from $1,6002024-01-10 HIGH 7.5 CVE-2024-0356 A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionalit… Ssm Shiro Blog No fix yet Fix from $1,9502024-01-10 HIGH 7.5 CVE-2024-0358 A vulnerability was found in DeShang DSO2O up to 4.1.0. It has been classified as critical. This affects an unknown part of the file /install/install… Dso2o after 4.1.0 Fix from $1,9502024-01-10 HIGH 7.0 CVE-2024-20657 Windows Group Policy Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20402 / 10.0.14393.6614+ Fix from $1,9502024-01-09 MEDIUM 6.5 CVE-2023-7223 A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cst… T6 Firmware No fix yet Fix from $1,6002024-01-09 HIGH 7.5 CVE-2023-49961 WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure. Bastion 9.0.10 / 10.0.6+ Fix from $1,9502024-01-08 HIGH 7.5 CVE-2024-21644EPSS 42% pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask… Pyload after 0.4.9 Fix from $1,9502024-01-08 HIGH 8.1 CVE-2023-29051 User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature … Ox App Suite 7.10.6+ Fix from $1,9502024-01-08 CRITICAL 10.0 CVE-2024-22216 In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote s… Maxview Storage Manager after 4.14.00.26064 Fix from $2,3002024-01-08 MEDIUM 6.5 CVE-2023-6733 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via… Wp Members after 3.4.8 Fix from $1,6002024-01-04 MEDIUM 6.5 CVE-2023-50343 HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Adm… Dryice Myxalytics Mitigation only Fix from $1,6002024-01-03 MEDIUM 5.4 CVE-2023-50344 HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download cert… Dryice Myxalytics Mitigation only Fix from $1,6002024-01-03 HIGH 7.5 CVE-2023-50341 HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, refl… Dryice Myxalytics Mitigation only Fix from $1,9502024-01-03 HIGH 8.1 CVE-2023-7193 A vulnerability was found in MTab Bookmark up to 1.2.6 and classified as critical. This issue affects some unknown processing of the file public/inst… Bookmark after 1.2.6 Fix from $1,9502023-12-31