Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Dynamics 365 HIGH 7.3
CVE-2024-30061

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Patch available
Fix from $1,950 2024-07-09
Unclassified HIGH 7.2
CVE-2024-39597

In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and …

Mitigation only
Fix from $1,950 2024-07-09
MongoDB MEDIUM 6.5
CVE-2024-6375

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to ei…

Fix: 5.0.22 / 6.0.11+
Fix from $1,600 2024-07-01
Authentik CRITICAL 9.8
CVE-2024-38371

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow…

Fix: 2024.2.4 / 2024.4.3+
Fix from $2,300 2024-06-28
Elastic Cloud Enterprise CRITICAL 9.8
CVE-2024-37282

It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently …

Fix: 3.7.2+
Fix from $2,300 2024-06-28
GitLab MEDIUM 6.5
CVE-2024-3959

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting …

Fix: 16.11.5 / 17.0.3+
Fix from $1,600 2024-06-27
Evmos MEDIUM 6.5
CVE-2024-37159

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a validator using vested tokens to…

Fix: 18.0.0+
Fix from $1,600 2024-06-17
Unclassified HIGH 7.1
CVE-2024-6000

The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the …

Mitigation only
Fix from $1,950 2024-06-15
Commerce HIGH 8.2
CVE-2024-34104

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in …

Fix: after 1.4.0
Fix from $1,950 2024-06-13
Networking Os10 HIGH 8.8
CVE-2024-25949

Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authentic…

Fix: 10.5.3.10 / 10.5.4.11+
Fix from $1,950 2024-06-12
Evmos MEDIUM 5.3
CVE-2024-37154

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects …

Mitigation only
Fix from $1,600 2024-06-06
Kanboard MEDIUM 6.3
CVE-2024-36399

Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php functio…

Fix: 1.2.37+
Fix from $1,600 2024-06-06
Fortiwebmanager HIGH 8.8
CVE-2024-23667

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…

Fix: 6.2.5 / 7.0.5+
Fix from $1,950 2024-06-03
Fortiwebmanager HIGH 8.8
CVE-2024-23670

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…

Fix: 6.2.5 / 7.0.5+
Fix from $1,950 2024-06-03
Fortiweb HIGH 8.8
CVE-2024-23665

Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, ver…

Fix: 7.2.8 / 7.4.3+
Fix from $1,950 2024-06-03
Unclassified CRITICAL 9.8
CVE-2024-36108

casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sens…

Patch available
Fix from $2,300 2024-05-31
Unclassified MEDIUM 5.4
CVE-2024-3269

The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstal…

Mitigation only
Fix from $1,600 2024-05-30
Unclassified MEDIUM 5.3
CVE-2024-0870

The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sav…

Mitigation only
Fix from $1,600 2024-05-14
Online Laundry Management System HIGH 8.8
CVE-2024-4819

A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function o…

No fix yet
Fix from $1,950 2024-05-14
Vikbooking Hotel Booking Engine \& Pms HIGH 8.1
CVE-2024-2441

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber…

Fix: 1.6.8+
Fix from $1,950 2024-05-14
Unclassified CRITICAL 9.8
CVE-2024-28285

A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in t…

No fix yet
Fix from $2,300 2024-05-14
Hcl Commerce HIGH 7.1
CVE-2024-23576

Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthori…

Fix: 9.1.14+
Fix from $1,950 2024-05-14
Ex1800t Firmware CRITICAL 9.8
CVE-2024-34257

TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary command…

No fix yet
Fix from $2,300 2024-05-08
Dedecms CRITICAL 9.1
CVE-2024-33749

DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.

No fix yet
Fix from $2,300 2024-05-06
Unclassified MEDIUM 6.1
CVE-2023-41819

A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized…

Mitigation only
Fix from $1,600 2024-05-03
D View 8 HIGH 8.8
CVE-2023-44410

D-Link D-View showUsers Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges …

Mitigation only
Fix from $1,950 2024-05-03
D View 8 HIGH 8.8
CVE-2023-32168

D-Link D-View showUser Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges o…

Fix: after 2.0.1.27
Fix from $1,950 2024-05-03
Unclassified MEDIUM 6.9
CVE-2024-32359

An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the sec…

Mitigation only
Fix from $1,600 2024-05-02
Ur32l Firmware HIGH 8.8
CVE-2023-47166

A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request…

Mitigation only
Fix from $1,950 2024-05-01
Unclassified CRITICAL 9.8
CVE-2024-32881

Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Token…

Patch available
Fix from $2,300 2024-04-26