Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified CRITICAL 9.8
CVE-2024-31695

A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication wh…

Mitigation only
Fix from $2,300 2024-11-14
Lunary HIGH 8.1
CVE-2024-3379

In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key f…

Fix: 1.2.7+
Fix from $1,950 2024-11-14
Harbor HIGH 7.7
CVE-2022-31670

Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an i…

Fix: 1.10.13 / 2.4.3+
Fix from $1,950 2024-11-14
Harbor HIGH 7.4
CVE-2022-31671

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request t…

Fix: 2.4.3 / 2.5.2+
Fix from $1,950 2024-11-14
Harbor MEDIUM 6.4
CVE-2022-31667

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access…

Fix: 2.4.3 / 2.5.2+
Fix from $1,600 2024-11-14
Harbor HIGH 7.7
CVE-2022-31668

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that…

Fix: 2.4.3 / 2.5.2+
Fix from $1,950 2024-11-14
Harbor HIGH 7.7
CVE-2022-31669

Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy wit…

Fix: 2.4.3 / 2.5.2+
Fix from $1,950 2024-11-14
GitLab HIGH 8.8
CVE-2024-9693

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting f…

Fix: 17.3.7 / 17.4.4+
Fix from $1,950 2024-11-14
Unclassified MEDIUM 6.5
CVE-2024-45877

baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.asp…

Mitigation only
Fix from $1,600 2024-11-13
Simatic Cp 1543 1 Firmware HIGH 7.5
CVE-2024-50310

A vulnerability has been identified in SIMATIC CP 1543-1 V4.0 (6GK7543-1AX10-0XE0) (All versions >= V4.0.44 < V4.0.50). Affected devices do not prope…

Fix: 4.0.50+
Fix from $1,950 2024-11-12
Moodle MEDIUM 5.3
CVE-2024-43433

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

Fix: 4.3.6 / 4.4.2+
Fix from $1,600 2024-11-11
Data.all MEDIUM 5.4
CVE-2024-52312

Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations ag…

Fix: 2.6.1+
Fix from $1,600 2024-11-09
Unclassified MEDIUM 6.5
CVE-2024-44765

An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users…

Mitigation only
Fix from $1,600 2024-11-08
Nomad HIGH 7.7
CVE-2024-10975

Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized C…

Fix: 1.7.15 / 1.8.7+
Fix from $1,950 2024-11-07
Identity Services Engine MEDIUM 6.5
CVE-2024-20537

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanis…

Mitigation only
Fix from $1,600 2024-11-06
Unclassified MEDIUM 6.3
CVE-2024-9902

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on …

Mitigation only
Fix from $1,600 2024-11-06
Lylme Spage CRITICAL 9.8
CVE-2024-48176

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not b…

Mitigation only
Fix from $2,300 2024-11-05
Chamilo Lms HIGH 8.8
CVE-2024-30616

Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, p…

Patch available
Fix from $1,950 2024-11-04
Secure Internet Access Enterprise Threatavert HIGH 7.1
CVE-2024-45164

Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Po…

No fix yet
Fix from $1,950 2024-11-04
Htaccess File Editor HIGH 8.8
CVE-2024-49256

Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionality Not Properly Constrained b…

Fix: 1.0.19+
Fix from $1,950 2024-11-01
Unclassified MEDIUM 5.7
CVE-2024-49501

Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may ac…

Mitigation only
Fix from $1,600 2024-11-01
Unclassified HIGH 8.8
CVE-2024-51425

An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact. NOTE: …

No fix yet
Fix from $1,950 2024-10-30
Unclassified HIGH 8.8
CVE-2024-51426

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the _…

No fix yet
Fix from $1,950 2024-10-30
Greenshift Animation And Page Builder Blocks CRITICAL 9.8
CVE-2024-50419

Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Acce…

Fix: 9.8+
Fix from $2,300 2024-10-30
Ipados CRITICAL 9.1
CVE-2024-44217

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password aut…

Fix: 18.0+
Fix from $2,300 2024-10-28
macOS MEDIUM 5.5
CVE-2024-44287

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious appli…

Fix: 13.7.1 / 14.7.1+
Fix from $1,600 2024-10-28
macOS HIGH 7.5
CVE-2024-44289

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, m…

Fix: 13.7.1 / 14.7.1+
Fix from $1,950 2024-10-28
macOS MEDIUM 5.5
CVE-2024-44301

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious appli…

Fix: 13.7.1 / 14.7.1+
Fix from $1,600 2024-10-28
macOS HIGH 8.6
CVE-2024-44270

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A sandbox…

Fix: 13.7.1 / 14.7.1+
Fix from $1,950 2024-10-28
macOS MEDIUM 5.5
CVE-2024-44247

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious appli…

Fix: 13.7.1 / 14.7.1+
Fix from $1,600 2024-10-28