Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Dir 816 Firmware MEDIUM 6.5
CVE-2024-57678

An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and…

Mitigation only
Fix from $1,600 2025-01-16
Dir 816 Firmware MEDIUM 6.5
CVE-2024-57679

An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the…

Mitigation only
Fix from $1,600 2025-01-16
Dir 816 Firmware MEDIUM 5.3
CVE-2024-57680

An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set th…

Mitigation only
Fix from $1,600 2025-01-16
Dir 816 Firmware MEDIUM 5.3
CVE-2024-57681

An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl servi…

Mitigation only
Fix from $1,600 2025-01-16
Dir 816 Firmware MEDIUM 6.5
CVE-2024-57676

An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set th…

Mitigation only
Fix from $1,600 2025-01-16
Ipados HIGH 7.8
CVE-2024-40771

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey …

Fix: 1.2 / 12.7.5+
Fix from $1,950 2025-01-15
On Prem Data Gateway MEDIUM 6.4
CVE-2025-21403

On-Premises Data Gateway Information Disclosure Vulnerability

Fix: 3000.246+
Fix from $1,600 2025-01-14
Pages Restriction Access MEDIUM 5.3
CVE-2024-13302

Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2…

Fix: 2.0.3+
Fix from $1,600 2025-01-09
Ohdear Integration MEDIUM 5.3
CVE-2024-13290

Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before …

Fix: 2.0.4+
Fix from $1,600 2025-01-09
Basic Http Authentication HIGH 7.3
CVE-2024-13291

Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from…

Fix: 7.x-1.4+
Fix from $1,950 2025-01-09
Canlineapp MEDIUM 6.5
CVE-2024-56114

Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improp…

No fix yet
Fix from $1,600 2025-01-09
Monster Menus CRITICAL 9.1
CVE-2024-13281

Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.

Fix: 7.x-1.34 / 9.3.2+
Fix from $2,300 2025-01-09
Block Permissions HIGH 8.8
CVE-2024-13282

Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.…

Fix: 1.2.0+
Fix from $1,950 2025-01-09
Smart Ip Ban CRITICAL 9.1
CVE-2024-13277

Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.

Fix: 7.x-1.1+
Fix from $2,300 2025-01-09
Diff CRITICAL 9.1
CVE-2024-13278

Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.

Fix: 1.8.0+
Fix from $2,300 2025-01-09
Responsive And Off Canvas Menu MEDIUM 5.3
CVE-2024-13266

Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas …

Fix: 4.4.4+
Fix from $1,600 2025-01-09
Advanced Pwa Inc Push Notifications CRITICAL 9.1
CVE-2024-13253

Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push…

Fix: 8.x-1.5+
Fix from $2,300 2025-01-09
Commerce View Receipt MEDIUM 5.3
CVE-2024-13257

Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 b…

Fix: 1.0.3+
Fix from $1,600 2025-01-09
Rest \& Json Api Authentication CRITICAL 9.8
CVE-2024-13258

Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON …

Fix: 2.0.13+
Fix from $2,300 2025-01-09
Firefox MEDIUM 5.4
CVE-2025-0237

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the prin…

Fix: 128.6.0 / 134.0+
Fix from $1,600 2025-01-07
Unclassified HIGH 7.5
CVE-2024-39025

Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.

Mitigation only
Fix from $1,950 2024-12-27
Mate 20 Firmware MEDIUM 6.8
CVE-2020-9081

There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to expl…

Fix: 10.1.0.88 / 10.1.0.160+
Fix from $1,600 2024-12-27
Magicos MEDIUM 5.5
CVE-2024-47148

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

Fix: 8.0.0.112+
Fix from $1,600 2024-12-26
Magicos MEDIUM 5.5
CVE-2024-47157

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

Fix: 8.0.0.135+
Fix from $1,600 2024-12-26
Theora CRITICAL 9.8
CVE-2024-56431

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parti…

Fix: 1.2.0+
Fix from $2,300 2024-12-25
Vios MEDIUM 5.5
CVE-2024-47102

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause…

Mitigation only
Fix from $1,600 2024-12-25
Ng Firewall HIGH 7.8
CVE-2024-12831

Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privil…

Mitigation only
Fix from $1,950 2024-12-20
Unclassified CRITICAL 10.0
CVE-2023-4617

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owne…

Mitigation only
Fix from $2,300 2024-12-19
Elasticsearch MEDIUM 6.5
CVE-2024-12539

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Leve…

Fix: 8.16.2+
Fix from $1,600 2024-12-17
Next.js HIGH 7.5
CVE-2024-51479

Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in m…

Fix: 14.2.15+
Fix from $1,950 2024-12-17