Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Unclassified HIGH 8.8
CVE-2024-10729

The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Mitigation only
Fix from $1,950 2024-11-26
Authentik HIGH 7.2
CVE-2024-52287

authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get …

Fix: 2024.8.5 / 2024.10.3+
Fix from $1,950 2024-11-21
Prime Data Center Network Manager MEDIUM 6.3
CVE-2020-3539

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to vi…

Fix: 11.4+
Fix from $1,600 2024-11-18
Unclassified MEDIUM 5.3
CVE-2024-11306

A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown…

Mitigation only
Fix from $1,600 2024-11-18
Glpi HIGH 7.5
CVE-2024-38370

GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API wi…

Fix: 10.0.16+
Fix from $1,950 2024-11-15
Unclassified CRITICAL 9.3
CVE-2024-52528

Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Contr…

Mitigation only
Fix from $2,300 2024-11-15
Harbor HIGH 7.7
CVE-2022-31670

Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an i…

Fix: 1.10.13 / 2.4.3+
Fix from $1,950 2024-11-14
Harbor HIGH 7.4
CVE-2022-31671

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request t…

Fix: 2.4.3 / 2.5.2+
Fix from $1,950 2024-11-14
Harbor MEDIUM 5.4
CVE-2022-31666

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of ot…

Fix: 2.4.3 / 2.5.2+
Fix from $1,600 2024-11-14
Harbor MEDIUM 6.4
CVE-2022-31667

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access…

Fix: 2.4.3 / 2.5.2+
Fix from $1,600 2024-11-14
Harbor HIGH 7.7
CVE-2022-31668

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that…

Fix: 2.4.3 / 2.5.2+
Fix from $1,950 2024-11-14
Harbor HIGH 7.7
CVE-2022-31669

Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy wit…

Fix: 2.4.3 / 2.5.2+
Fix from $1,950 2024-11-14
Azure Cyclecloud CRITICAL 9.9
CVE-2024-43602

Azure CycleCloud Remote Code Execution Vulnerability

Fix: 8.6.5+
Fix from $2,300 2024-11-12
Hospital Management System HIGH 8.1
CVE-2024-11073

A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /…

No fix yet
Fix from $1,950 2024-11-11
Harmonyos MEDIUM 5.5
CVE-2024-51525

Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2024-11-05
Lr350 Firmware CRITICAL 9.1
CVE-2024-10654

A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functiona…

No fix yet
Fix from $2,300 2024-11-01
Office Anywhere MEDIUM 6.5
CVE-2024-10598

A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/h…

Fix: after 11.6
Fix from $1,600 2024-10-31
Mapster Wp Maps HIGH 8.8
CVE-2024-9235

The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insuffici…

Fix: after 1.5.0
Fix from $1,950 2024-10-25
Unclassified MEDIUM 5.3
CVE-2020-36841

The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_…

Mitigation only
Fix from $1,600 2024-10-16
Sakai HIGH 8.8
CVE-2024-47876

Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can lo…

Fix: 23.2+
Fix from $1,950 2024-10-15
Artemis HIGH 8.8
CVE-2023-50780EPSS 17%

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia…

Fix: 2.29.0+
Fix from $1,950 2024-10-14
Gradio HIGH 8.3
CVE-2024-47084

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio…

Fix: 4.44.0+
Fix from $1,950 2024-10-10
Gradio MEDIUM 5.4
CVE-2024-47165

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origi…

Fix: 5.0.0+
Fix from $1,600 2024-10-10
Windows Server 2022 23h2 MEDIUM 6.6
CVE-2024-38129

Windows Kerberos Elevation of Privilege Vulnerability

Fix: 10.0.25398.1189+
Fix from $1,600 2024-10-08
Wsa8835 Firmware MEDIUM 6.1
CVE-2024-38425

Information disclosure while sending implicit broadcast containing APP launch information.

Mitigation only
Fix from $1,600 2024-10-07
Parse Server HIGH 8.1
CVE-2024-47183

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectI…

Fix: 6.5.9 / 7.3.0+
Fix from $1,950 2024-10-04
Rv340 Dual Wan Gigabit Vpn Router Firmware HIGH 8.8
CVE-2024-20393

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could all…

Mitigation only
Fix from $1,950 2024-10-02
Nexus Dashboard MEDIUM 6.5
CVE-2024-20441

A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive inform…

Fix: 3.2 / 12.2.2+
Fix from $1,600 2024-10-02
Railway Reservation System MEDIUM 6.3
CVE-2024-9297

A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Affected by this vulnerability i…

No fix yet
Fix from $1,600 2024-09-28
Ios Xe MEDIUM 6.5
CVE-2024-20414

A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cr…

Mitigation only
Fix from $1,600 2024-09-25