Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 7.3 CVE-2024-30061 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability Dynamics 365 Patch available Fix from $1,9502024-07-09 HIGH 7.2 CVE-2024-39597 In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and … Mitigation only Fix from $1,9502024-07-09 MEDIUM 6.5 CVE-2024-6375 A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to ei… MongoDB 5.0.22 / 6.0.11+ Fix from $1,6002024-07-01 CRITICAL 9.8 CVE-2024-38371 authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow… Authentik 2024.2.4 / 2024.4.3+ Fix from $2,3002024-06-28 CRITICAL 9.8 CVE-2024-37282 It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently … Elastic Cloud Enterprise 3.7.2+ Fix from $2,3002024-06-28 MEDIUM 6.5 CVE-2024-3959 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting … GitLab 16.11.5 / 17.0.3+ Fix from $1,6002024-06-27 MEDIUM 6.5 CVE-2024-37159 Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a validator using vested tokens to… Evmos 18.0.0+ Fix from $1,6002024-06-17 HIGH 7.1 CVE-2024-6000 The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the … Mitigation only Fix from $1,9502024-06-15 HIGH 8.2 CVE-2024-34104 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in … Commerce after 1.4.0 Fix from $1,9502024-06-13 HIGH 8.8 CVE-2024-25949 Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authentic… Networking Os10 10.5.3.10 / 10.5.4.11+ Fix from $1,9502024-06-12 MEDIUM 5.3 CVE-2024-37154 Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects … Evmos Mitigation only Fix from $1,6002024-06-06 MEDIUM 6.3 CVE-2024-36399 Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php functio… Kanboard 1.2.37+ Fix from $1,6002024-06-06 HIGH 8.8 CVE-2024-23667 An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug… Fortiwebmanager 6.2.5 / 7.0.5+ Fix from $1,9502024-06-03 HIGH 8.8 CVE-2024-23670 An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug… Fortiwebmanager 6.2.5 / 7.0.5+ Fix from $1,9502024-06-03 HIGH 8.8 CVE-2024-23665 Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, ver… Fortiweb 7.2.8 / 7.4.3+ Fix from $1,9502024-06-03 CRITICAL 9.8 CVE-2024-36108 casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sens… Patch available Fix from $2,3002024-05-31 MEDIUM 5.4 CVE-2024-3269 The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstal… Mitigation only Fix from $1,6002024-05-30 MEDIUM 5.3 CVE-2024-0870 The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sav… Mitigation only Fix from $1,6002024-05-14 HIGH 8.8 CVE-2024-4819 A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function o… Online Laundry Management System No fix yet Fix from $1,9502024-05-14 HIGH 8.1 CVE-2024-2441 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber… Vikbooking Hotel Booking Engine \& Pms 1.6.8+ Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-28285 A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in t… No fix yet Fix from $2,3002024-05-14 HIGH 7.1 CVE-2024-23576 Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthori… Hcl Commerce 9.1.14+ Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-34257 TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary command… Ex1800t Firmware No fix yet Fix from $2,3002024-05-08 CRITICAL 9.1 CVE-2024-33749 DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php. Dedecms No fix yet Fix from $2,3002024-05-06 MEDIUM 6.1 CVE-2023-41819 A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized… Mitigation only Fix from $1,6002024-05-03 HIGH 8.8 CVE-2023-44410 D-Link D-View showUsers Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges … D View 8 Mitigation only Fix from $1,9502024-05-03 HIGH 8.8 CVE-2023-32168 D-Link D-View showUser Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges o… D View 8 after 2.0.1.27 Fix from $1,9502024-05-03 MEDIUM 6.9 CVE-2024-32359 An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the sec… Mitigation only Fix from $1,6002024-05-02 HIGH 8.8 CVE-2023-47166 A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request… Ur32l Firmware Mitigation only Fix from $1,9502024-05-01 CRITICAL 9.8 CVE-2024-32881 Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Token… Patch available Fix from $2,3002024-04-26