Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 8.1 CVE-2023-50363 An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al… Qts Mitigation only Fix from $1,9502024-04-26 MEDIUM 6.5 CVE-2023-5675 A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or custo… Mitigation only Fix from $1,6002024-04-25 HIGH 7.5 CVE-2024-3840 Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions… Chrome 124.0.6367.60+ Fix from $1,9502024-04-17 MEDIUM 6.1 CVE-2024-21039 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a… Complex Maintenance Repair And Overhaul after 12.2.13 Fix from $1,6002024-04-16 MEDIUM 6.1 CVE-2024-21035 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a… Complex Maintenance Repair And Overhaul after 12.2.13 Fix from $1,6002024-04-16 HIGH 7.1 CVE-2024-21026 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a… Complex Maintenance Repair And Overhaul after 12.2.13 Fix from $1,9502024-04-16 MEDIUM 6.1 CVE-2024-21031 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a… Complex Maintenance Repair And Overhaul after 12.2.13 Fix from $1,6002024-04-16 MEDIUM 6.1 CVE-2024-21018 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a… Complex Maintenance Repair And Overhaul after 12.2.13 Fix from $1,6002024-04-16 MEDIUM 6.4 CVE-2024-3027 The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function i… Mitigation only Fix from $1,6002024-04-13 MEDIUM 5.4 CVE-2024-1289 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.… Learnpress 4.2.6.4+ Fix from $1,6002024-04-09 MEDIUM 6.4 CVE-2024-26193 Azure Migrate Remote Code Execution Vulnerability Azure Migrate 6.1.294.1003+ Fix from $1,6002024-04-09 HIGH 7.5 CVE-2023-52359 Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability… Emui Mitigation only Fix from $1,9502024-04-08 HIGH 7.5 CVE-2023-52539 Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentialit… Emui Mitigation only Fix from $1,9502024-04-08 MEDIUM 5.4 CVE-2024-3434 A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability is an unknown functionality o… Mitigation only Fix from $1,6002024-04-08 MEDIUM 5.4 CVE-2024-3139 A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue… Computer Laboratory Management System No fix yet Fix from $1,6002024-04-01 HIGH 8.8 CVE-2024-3013EPSS 23% A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools/test_login.php?action=regist… Flir Ax8 Firmware after 1.46.16 Fix from $1,9502024-03-28 HIGH 7.8 CVE-2024-0077 NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, where it allows a guest OS to allocate resources for which the guest OS is no… Mitigation only Fix from $1,9502024-03-27 CRITICAL 9.1 CVE-2024-29033 OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any O… Oauthenticator 16.3.0+ Fix from $2,3002024-03-20 MEDIUM 5.3 CVE-2024-2641 A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been classified as critical. Affected is an unknown function of the file /sy… Rg Nbs2009g P Firmware Mitigation only Fix from $1,6002024-03-19 MEDIUM 6.5 CVE-2024-27930 GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authe… Glpi 10.0.13+ Fix from $1,6002024-03-18 CRITICAL 9.1 CVE-2024-2557 A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of… Food Waste Management System No fix yet Fix from $2,3002024-03-17 CRITICAL 9.1 CVE-2024-2317 A vulnerability was found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This issue affects some unknown processing of … Hospital Automanager after 2024-02-27 Fix from $2,3002024-03-08 HIGH 7.5 CVE-2024-25063 Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that th… Hikcentral Professional after 2.5.1 Fix from $1,9502024-03-02 HIGH 7.3 CVE-2024-24900 Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adjacent network low privileged a… Policy Manager For Secure Connect Gateway 5.22.00.16+ Fix from $1,9502024-03-01 MEDIUM 6.5 CVE-2024-1043 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'a… Accelerated Mobile Pages 1.0.93.2+ Fix from $1,6002024-02-29 MEDIUM 5.4 CVE-2024-20943 Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are af… Knowledge Management after 12.2.13 Fix from $1,6002024-02-17 MEDIUM 5.4 CVE-2024-21987 SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter Server user to modify system … Snapcenter 5.0+ Fix from $1,6002024-02-16 MEDIUM 6.7 CVE-2023-38135 Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of privilege via local access. Performance Maximizer Mitigation only Fix from $1,6002024-02-14 HIGH 7.1 CVE-2024-21402 Microsoft Outlook Elevation of Privilege Vulnerability 365 Apps after 2401.17231.20236 Fix from $1,9502024-02-13 HIGH 8.8 CVE-2024-25108 Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attacke… Pixelfed 0.11.11+ Fix from $1,9502024-02-12