Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Qts HIGH 8.1
CVE-2023-50363

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…

Mitigation only
Fix from $1,950 2024-04-26
Unclassified MEDIUM 6.5
CVE-2023-5675

A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or custo…

Mitigation only
Fix from $1,600 2024-04-25
Chrome HIGH 7.5
CVE-2024-3840

Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions…

Fix: 124.0.6367.60+
Fix from $1,950 2024-04-17
Complex Maintenance Repair And Overhaul MEDIUM 6.1
CVE-2024-21039

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a…

Fix: after 12.2.13
Fix from $1,600 2024-04-16
Complex Maintenance Repair And Overhaul MEDIUM 6.1
CVE-2024-21035

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a…

Fix: after 12.2.13
Fix from $1,600 2024-04-16
Complex Maintenance Repair And Overhaul HIGH 7.1
CVE-2024-21026

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a…

Fix: after 12.2.13
Fix from $1,950 2024-04-16
Complex Maintenance Repair And Overhaul MEDIUM 6.1
CVE-2024-21031

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a…

Fix: after 12.2.13
Fix from $1,600 2024-04-16
Complex Maintenance Repair And Overhaul MEDIUM 6.1
CVE-2024-21018

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a…

Fix: after 12.2.13
Fix from $1,600 2024-04-16
Unclassified MEDIUM 6.4
CVE-2024-3027

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function i…

Mitigation only
Fix from $1,600 2024-04-13
Learnpress MEDIUM 5.4
CVE-2024-1289

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.…

Fix: 4.2.6.4+
Fix from $1,600 2024-04-09
Azure Migrate MEDIUM 6.4
CVE-2024-26193

Azure Migrate Remote Code Execution Vulnerability

Fix: 6.1.294.1003+
Fix from $1,600 2024-04-09
Emui HIGH 7.5
CVE-2023-52359

Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability…

Mitigation only
Fix from $1,950 2024-04-08
Emui HIGH 7.5
CVE-2023-52539

Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentialit…

Mitigation only
Fix from $1,950 2024-04-08
Unclassified MEDIUM 5.4
CVE-2024-3434

A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability is an unknown functionality o…

Mitigation only
Fix from $1,600 2024-04-08
Computer Laboratory Management System MEDIUM 5.4
CVE-2024-3139

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue…

No fix yet
Fix from $1,600 2024-04-01
Flir Ax8 Firmware HIGH 8.8
CVE-2024-3013EPSS 23%

A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools/test_login.php?action=regist…

Fix: after 1.46.16
Fix from $1,950 2024-03-28
Unclassified HIGH 7.8
CVE-2024-0077

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, where it allows a guest OS to allocate resources for which the guest OS is no…

Mitigation only
Fix from $1,950 2024-03-27
Oauthenticator CRITICAL 9.1
CVE-2024-29033

OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any O…

Fix: 16.3.0+
Fix from $2,300 2024-03-20
Rg Nbs2009g P Firmware MEDIUM 5.3
CVE-2024-2641

A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been classified as critical. Affected is an unknown function of the file /sy…

Mitigation only
Fix from $1,600 2024-03-19
Glpi MEDIUM 6.5
CVE-2024-27930

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authe…

Fix: 10.0.13+
Fix from $1,600 2024-03-18
Food Waste Management System CRITICAL 9.1
CVE-2024-2557

A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of…

No fix yet
Fix from $2,300 2024-03-17
Hospital Automanager CRITICAL 9.1
CVE-2024-2317

A vulnerability was found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This issue affects some unknown processing of …

Fix: after 2024-02-27
Fix from $2,300 2024-03-08
Hikcentral Professional HIGH 7.5
CVE-2024-25063

Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that th…

Fix: after 2.5.1
Fix from $1,950 2024-03-02
Policy Manager For Secure Connect Gateway HIGH 7.3
CVE-2024-24900

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adjacent network low privileged a…

Fix: 5.22.00.16+
Fix from $1,950 2024-03-01
Accelerated Mobile Pages MEDIUM 6.5
CVE-2024-1043

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'a…

Fix: 1.0.93.2+
Fix from $1,600 2024-02-29
Knowledge Management MEDIUM 5.4
CVE-2024-20943

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are af…

Fix: after 12.2.13
Fix from $1,600 2024-02-17
Snapcenter MEDIUM 5.4
CVE-2024-21987

SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter Server user to modify system …

Fix: 5.0+
Fix from $1,600 2024-02-16
Performance Maximizer MEDIUM 6.7
CVE-2023-38135

Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of privilege via local access.

Mitigation only
Fix from $1,600 2024-02-14
365 Apps HIGH 7.1
CVE-2024-21402

Microsoft Outlook Elevation of Privilege Vulnerability

Fix: after 2401.17231.20236
Fix from $1,950 2024-02-13
Pixelfed HIGH 8.8
CVE-2024-25108

Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attacke…

Fix: 0.11.11+
Fix from $1,950 2024-02-12