Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Online Eyewear Shop CRITICAL 9.8
CVE-2024-9082

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functional…

No fix yet
Fix from $2,300 2024-09-22
Dynamics 365 Business Central HIGH 8.8
CVE-2024-43460

Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over …

Patch available
Fix from $1,950 2024-09-17
Model Driven Service Abstraction Layer MEDIUM 6.5
CVE-2024-46942

In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an Op…

Fix: after 13.0.1
Fix from $1,600 2024-09-15
Unclassified MEDIUM 6.6
CVE-2024-6840

An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP req…

Mitigation only
Fix from $1,600 2024-09-12
Ios Xr HIGH 8.8
CVE-2024-20381

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management…

Mitigation only
Fix from $1,950 2024-09-11
Outlook MEDIUM 6.5
CVE-2024-43482

Microsoft Outlook for iOS Information Disclosure Vulnerability

Fix: 4.2435.0+
Fix from $1,600 2024-09-10
Windows Server 2008 HIGH 7.5
CVE-2024-38231

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

Fix: 10.0.14393.7336 / 10.0.17763.6293+
Fix from $1,950 2024-09-10
Unclassified HIGH 8.8
CVE-2024-45044

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes …

Patch available
Fix from $1,950 2024-09-10
Unclassified HIGH 7.5
CVE-2024-8509

A vulnerability was found in Forklift Controller.  There is no verification against the authorization header except to ensure it uses bearer authenti…

Mitigation only
Fix from $1,950 2024-09-06
Emui HIGH 7.5
CVE-2024-42039

Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2024-09-04
Sudobot CRITICAL 9.8
CVE-2024-45307

SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is …

Fix: 9.26.7+
Fix from $2,300 2024-09-03
Unclassified MEDIUM 5.1
CVE-2024-34463

BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authent…

Mitigation only
Fix from $1,600 2024-09-03
Authentik HIGH 7.5
CVE-2024-42490

authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main …

Fix: 2024.4.4 / 2024.6.4+
Fix from $1,950 2024-08-22
Yoga Class Registration System CRITICAL 9.8
CVE-2024-7851

A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown co…

No fix yet
Fix from $2,300 2024-08-16
Blind Spot Detection Sensor Ecu Firmware MEDIUM 6.5
CVE-2024-6347

* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to…

Mitigation only
Fix from $1,600 2024-08-15
Zephyr Project Manager HIGH 8.1
CVE-2024-7624

The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is …

Fix: 3.3.102+
Fix from $1,950 2024-08-15
Simple Online Bidding System HIGH 7.3
CVE-2024-7799

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown f…

No fix yet
Fix from $1,950 2024-08-15
Commerce MEDIUM 5.4
CVE-2024-39418

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result …

Fix: after 2.4.3
Fix from $1,600 2024-08-14
MongoDB MEDIUM 5.3
CVE-2024-6384

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoD…

Fix: 6.0.16 / 7.0.11+
Fix from $1,600 2024-08-13
Emui HIGH 7.5
CVE-2024-42036

Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confident…

No fix yet
Fix from $1,950 2024-08-08
Emui MEDIUM 5.5
CVE-2024-42032

Access permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect service confiden…

No fix yet
Fix from $1,600 2024-08-08
Alr F800 Firmware CRITICAL 9.8
CVE-2024-7578

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the …

Fix: after 19.10.24
Fix from $2,300 2024-08-07
Endpoint Manager Mobile CRITICAL 9.8
CVE-2024-36130

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute …

Fix: 12.1.0.1+
Fix from $2,300 2024-08-07
Bostr MEDIUM 6.3
CVE-2024-41962

Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authorized_keys being set when noscr…

Fix: 3.0.10+
Fix from $1,600 2024-08-01
macOS MEDIUM 5.5
CVE-2024-40807

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut m…

Fix: 12.7.6 / 13.6.8+
Fix from $1,600 2024-07-29
macOS HIGH 7.1
CVE-2024-40814

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Ventura 13.7. An app may b…

Fix: 14.6+
Fix from $1,950 2024-07-29
macOS MEDIUM 5.5
CVE-2024-40783

The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ve…

Fix: 12.7.6 / 13.6.8+
Fix from $1,600 2024-07-29
Unclassified HIGH 7.5
CVE-2024-41670

In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a maliciou…

Mitigation only
Fix from $1,950 2024-07-26
MySQL MEDIUM 5.9
CVE-2024-21166

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 …

Fix: after 8.0.36
Fix from $1,600 2024-07-16
Unclassified HIGH 7.3
CVE-2024-36438

eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card dupli…

Mitigation only
Fix from $1,950 2024-07-15