Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified CRITICAL 9.1
CVE-2024-54662

Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.

Mitigation only
Fix from $2,300 2024-12-17
Dctrack HIGH 7.5
CVE-2024-37775

Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.

Mitigation only
Fix from $1,950 2024-12-16
GitLab MEDIUM 5.3
CVE-2024-8116

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a s…

Fix: 17.4.6 / 17.5.4+
Fix from $1,600 2024-12-16
GitLab MEDIUM 5.3
CVE-2024-8650

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed…

Fix: 17.4.6 / 17.5.4+
Fix from $1,600 2024-12-16
Xwiki HIGH 8.8
CVE-2024-55662

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extensio…

Fix: 15.10.9 / 16.3.0+
Fix from $1,950 2024-12-12
Superset MEDIUM 6.5
CVE-2024-55633

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed…

Fix: 4.1.0+
Fix from $1,600 2024-12-12
macOS MEDIUM 5.5
CVE-2024-54495

The issue was addressed with improved permissions logic. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to modify…

Fix: 14.7.2 / 15.2+
Fix from $1,600 2024-12-12
Superset MEDIUM 6.5
CVE-2024-53949

Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users …

Fix: 4.1.0+
Fix from $1,600 2024-12-09
Unclassified HIGH 8.8
CVE-2024-55579

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create …

Mitigation only
Fix from $1,950 2024-12-09
Devolutions Server MEDIUM 6.5
CVE-2024-12196

Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password hi…

Fix: 2024.3.8.0+
Fix from $1,600 2024-12-04
Veeam Backup \& Replication MEDIUM 6.5
CVE-2024-42451

A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a s…

Fix: 12.3.0.310+
Fix from $1,600 2024-12-04
Veeam Backup \& Replication HIGH 8.8
CVE-2024-42452

A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectiv…

Fix: 12.3.0.310+
Fix from $1,950 2024-12-04
Ozone HIGH 8.1
CVE-2024-45106

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…

Mitigation only
Fix from $1,950 2024-12-03
Unclassified HIGH 8.8
CVE-2024-53937

An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by defau…

Mitigation only
Fix from $1,950 2024-12-02
Unclassified HIGH 8.8
CVE-2024-53941

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote attacker (in proximity to a W…

Mitigation only
Fix from $1,950 2024-12-02
Unclassified CRITICAL 9.1
CVE-2024-52732

Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system being reused.

Mitigation only
Fix from $2,300 2024-12-02
Unclassified HIGH 7.5
CVE-2024-36611

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where t…

Patch available
Fix from $1,950 2024-11-29
Unclassified HIGH 7.5
CVE-2024-48651

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups…

Patch available
Fix from $1,950 2024-11-29
Unclassified HIGH 8.8
CVE-2024-54124

In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.

Mitigation only
Fix from $1,950 2024-11-29
Android HIGH 7.8
CVE-2018-9374

In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User…

Patch available
Fix from $1,950 2024-11-28
GitLab HIGH 7.5
CVE-2024-11669

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API end…

Fix: 17.4.5 / 17.5.3+
Fix from $1,950 2024-11-26
Unclassified HIGH 7.8
CVE-2024-7915

The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform multiple operations as the ro…

Mitigation only
Fix from $1,950 2024-11-25
Remote Desktop Manager MEDIUM 5.4
CVE-2024-11670

Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malici…

Fix: after 2024.3.10.0
Fix from $1,600 2024-11-25
Unclassified MEDIUM 5.3
CVE-2024-11176

Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorre…

Mitigation only
Fix from $1,600 2024-11-20
Android HIGH 7.8
CVE-2023-21270

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to …

Patch available
Fix from $1,950 2024-11-19
Agile Product Lifecycle Management HIGH 7.5
CVE-2024-21287 KEV

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The suppor…

Mitigation only
Fix from $1,950 2024-11-18
Autolab MEDIUM 5.4
CVE-2024-52584

Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view…

Patch available
Fix from $1,600 2024-11-18
Nextcloud Server MEDIUM 5.4
CVE-2024-52518

Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would b…

Fix: 28.0.12 / 29.0.9+
Fix from $1,600 2024-11-15
Unclassified HIGH 7.5
CVE-2024-50647

The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access …

Mitigation only
Fix from $1,950 2024-11-15
Python Book HIGH 7.5
CVE-2024-50650

python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by mod…

No fix yet
Fix from $1,950 2024-11-15