Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 8.8 CVE-2024-10729 The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … Mitigation only Fix from $1,9502024-11-26 HIGH 7.2 CVE-2024-52287 authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get … Authentik 2024.8.5 / 2024.10.3+ Fix from $1,9502024-11-21 MEDIUM 6.3 CVE-2020-3539 A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to vi… Prime Data Center Network Manager 11.4+ Fix from $1,6002024-11-18 MEDIUM 5.3 CVE-2024-11306 A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown… Mitigation only Fix from $1,6002024-11-18 HIGH 7.5 CVE-2024-38370 GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API wi… Glpi 10.0.16+ Fix from $1,9502024-11-15 CRITICAL 9.3 CVE-2024-52528 Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Contr… Mitigation only Fix from $2,3002024-11-15 HIGH 7.7 CVE-2022-31670 Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an i… Harbor 1.10.13 / 2.4.3+ Fix from $1,9502024-11-14 HIGH 7.4 CVE-2022-31671 Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request t… Harbor 2.4.3 / 2.5.2+ Fix from $1,9502024-11-14 MEDIUM 5.4 CVE-2022-31666 Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of ot… Harbor 2.4.3 / 2.5.2+ Fix from $1,6002024-11-14 MEDIUM 6.4 CVE-2022-31667 Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access… Harbor 2.4.3 / 2.5.2+ Fix from $1,6002024-11-14 HIGH 7.7 CVE-2022-31668 Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that… Harbor 2.4.3 / 2.5.2+ Fix from $1,9502024-11-14 HIGH 7.7 CVE-2022-31669 Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy wit… Harbor 2.4.3 / 2.5.2+ Fix from $1,9502024-11-14 CRITICAL 9.9 CVE-2024-43602 Azure CycleCloud Remote Code Execution Vulnerability Azure Cyclecloud 8.6.5+ Fix from $2,3002024-11-12 HIGH 8.1 CVE-2024-11073 A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /… Hospital Management System No fix yet Fix from $1,9502024-11-11 MEDIUM 5.5 CVE-2024-51525 Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos No fix yet Fix from $1,6002024-11-05 CRITICAL 9.1 CVE-2024-10654 A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functiona… Lr350 Firmware No fix yet Fix from $2,3002024-11-01 MEDIUM 6.5 CVE-2024-10598 A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/h… Office Anywhere after 11.6 Fix from $1,6002024-10-31 HIGH 8.8 CVE-2024-9235 The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insuffici… Mapster Wp Maps after 1.5.0 Fix from $1,9502024-10-25 MEDIUM 5.3 CVE-2020-36841 The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_… Mitigation only Fix from $1,6002024-10-16 HIGH 8.8 CVE-2024-47876 Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can lo… Sakai 23.2+ Fix from $1,9502024-10-15 HIGH 8.8 CVE-2023-50780EPSS 17% Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia… Artemis 2.29.0+ Fix from $1,9502024-10-14 HIGH 8.3 CVE-2024-47084 Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio… Gradio 4.44.0+ Fix from $1,9502024-10-10 MEDIUM 5.4 CVE-2024-47165 Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origi… Gradio 5.0.0+ Fix from $1,6002024-10-10 MEDIUM 6.6 CVE-2024-38129 Windows Kerberos Elevation of Privilege Vulnerability Windows Server 2022 23h2 10.0.25398.1189+ Fix from $1,6002024-10-08 MEDIUM 6.1 CVE-2024-38425 Information disclosure while sending implicit broadcast containing APP launch information. Wsa8835 Firmware Mitigation only Fix from $1,6002024-10-07 HIGH 8.1 CVE-2024-47183 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectI… Parse Server 6.5.9 / 7.3.0+ Fix from $1,9502024-10-04 HIGH 8.8 CVE-2024-20393 A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could all… Rv340 Dual Wan Gigabit Vpn Router Firmware Mitigation only Fix from $1,9502024-10-02 MEDIUM 6.5 CVE-2024-20441 A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive inform… Nexus Dashboard 3.2 / 12.2.2+ Fix from $1,6002024-10-02 MEDIUM 6.3 CVE-2024-9297 A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Affected by this vulnerability i… Railway Reservation System No fix yet Fix from $1,6002024-09-28 MEDIUM 6.5 CVE-2024-20414 A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cr… Ios Xe Mitigation only Fix from $1,6002024-09-25