Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
macOS MEDIUM 5.5
CVE-2024-44253

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be abl…

Fix: 13.7.1 / 14.7.1+
Fix from $1,600 2024-10-28
macOS MEDIUM 5.5
CVE-2024-44196

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1.…

Fix: 13.7.1 / 14.7.1+
Fix from $1,600 2024-10-28
macOS MEDIUM 5.5
CVE-2024-40855

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2. A sandb…

Fix: 13.7.1 / 14.7.1+
Fix from $1,600 2024-10-28
Unclassified MEDIUM 5.4
CVE-2024-9825

The Chef Habitat builder-api on-prem-builder package  with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect …

Mitigation only
Fix from $1,600 2024-10-28
Slurm MEDIUM 5.0
CVE-2024-48936

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute process…

Fix: 24.05.4+
Fix from $1,600 2024-10-28
Wtcms CRITICAL 9.8
CVE-2024-48237

WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.

No fix yet
Fix from $2,300 2024-10-25
Ovaledge HIGH 8.8
CVE-2022-30358

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw pa…

Fix: after 5.2.8
Fix from $1,950 2024-10-25
Autolab HIGH 8.8
CVE-2024-49376

Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0.…

Patch available
Fix from $1,950 2024-10-25
Android MEDIUM 5.5
CVE-2024-47025

In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information di…

Mitigation only
Fix from $1,600 2024-10-25
Android MEDIUM 5.5
CVE-2024-44099

There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additi…

No fix yet
Fix from $1,600 2024-10-25
Unclassified CRITICAL 9.8
CVE-2024-41617

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions…

Patch available
Fix from $2,300 2024-10-24
Mt2500 Firmware HIGH 8.0
CVE-2024-45261

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific use…

Fix: 4.6.4+
Fix from $1,950 2024-10-24
Mt6000 Firmware HIGH 8.0
CVE-2024-45260

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized gro…

Fix: 4.6.4+
Fix from $1,950 2024-10-24
3scale Api Management HIGH 7.5
CVE-2024-10295

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified HIGH 8.4
CVE-2024-48541

Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to access sensitive information by an…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified HIGH 8.4
CVE-2024-48542

Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive in…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified HIGH 8.4
CVE-2024-48544

Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified HIGH 8.4
CVE-2024-48545

Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyz…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified HIGH 8.4
CVE-2024-48546

Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyz…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified HIGH 8.4
CVE-2024-48547

Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information b…

Mitigation only
Fix from $1,950 2024-10-24
Unclassified CRITICAL 9.3
CVE-2024-48548

The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows attackers to …

Mitigation only
Fix from $2,300 2024-10-24
Unclassified MEDIUM 6.2
CVE-2024-48540

Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file.

Mitigation only
Fix from $1,600 2024-10-24
Secure Firewall Management Center MEDIUM 6.5
CVE-2024-20482

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center…

Mitigation only
Fix from $1,600 2024-10-23
Umbraco Cms MEDIUM 6.5
CVE-2024-48925

Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version …

Fix: 14.3.0+
Fix from $1,600 2024-10-22
Digital Experience Platform HIGH 8.8
CVE-2024-38002

The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th…

Fix: 7.4.3.112 / 2023.q3.9+
Fix from $1,950 2024-10-22
Ddmq HIGH 7.5
CVE-2024-10173

A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the compone…

No fix yet
Fix from $1,950 2024-10-20
Desktop \& Server Management HIGH 7.8
CVE-2024-29213

Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified …

Fix: 2024.2+
Fix from $1,950 2024-10-18
Desktop \& Server Management HIGH 7.8
CVE-2024-29821

Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified …

Fix: 2024.2+
Fix from $1,950 2024-10-18
Ata 191 Firmware HIGH 8.8
CVE-2024-20420

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote …

Fix: 11.2.5 / 12.0.2+
Fix from $1,950 2024-10-16
Solr CRITICAL 9.8
CVE-2024-45216EPSS 91%

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…

Fix: 8.11.4 / 9.7.0+
Fix from $2,300 2024-10-16