Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
GitLab MEDIUM 6.5
CVE-2024-9623

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting f…

Fix: 17.2.9 / 17.3.5+
Fix from $1,600 2024-10-10
Commerce MEDIUM 6.5
CVE-2024-45132

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result…

Mitigation only
Fix from $1,600 2024-10-10
Commerce MEDIUM 5.4
CVE-2024-45128

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result…

Mitigation only
Fix from $1,600 2024-10-10
Commerce MEDIUM 5.4
CVE-2024-45131

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result…

Mitigation only
Fix from $1,600 2024-10-10
Open Webui MEDIUM 5.4
CVE-2024-7048

In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/…

No fix yet
Fix from $1,600 2024-10-10
Unclassified CRITICAL 9.1
CVE-2024-45160

Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty…

Mitigation only
Fix from $2,300 2024-10-09
Wsa8835 Firmware MEDIUM 6.1
CVE-2024-38425

Information disclosure while sending implicit broadcast containing APP launch information.

Mitigation only
Fix from $1,600 2024-10-07
Parse Server HIGH 8.1
CVE-2024-47183

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectI…

Fix: 6.5.9 / 7.3.0+
Fix from $1,950 2024-10-04
Unclassified MEDIUM 6.8
CVE-2024-47616

Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all persistent Pomerium applicati…

Patch available
Fix from $1,600 2024-10-02
Unclassified HIGH 7.8
CVE-2024-47560

RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes…

Mitigation only
Fix from $1,950 2024-10-01
Computer Vision Annotation Tool MEDIUM 5.4
CVE-2024-47172

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may ret…

Fix: 2.19.1+
Fix from $1,600 2024-09-30
Authentik MEDIUM 6.5
CVE-2024-47077

authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that…

Fix: 2024.6.5 / 2024.8.3+
Fix from $1,600 2024-09-27
Emui HIGH 7.5
CVE-2024-9136

Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service co…

No fix yet
Fix from $1,950 2024-09-27
Cybermath CRITICAL 9.8
CVE-2024-7108

Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by A…

Mitigation only
Fix from $2,300 2024-09-26
Ios Xe CRITICAL 9.3
CVE-2024-20510

A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adj…

Mitigation only
Fix from $2,300 2024-09-25
Meshtastic Firmware CRITICAL 9.8
CVE-2024-47078

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or p…

Fix: 2.5.1+
Fix from $2,300 2024-09-25
Devolutions Server MEDIUM 6.5
CVE-2024-6512

Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permiss…

Fix: 2024.3.0+
Fix from $1,600 2024-09-25
Authentication Gateway CRITICAL 9.1
CVE-2024-6592

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Wi…

Fix: after 12.10.2
Fix from $2,300 2024-09-25
Authentication Gateway CRITICAL 9.1
CVE-2024-6593

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network acce…

Fix: after 12.10.2
Fix from $2,300 2024-09-25
Checkmk HIGH 8.8
CVE-2024-8606

Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication

Mitigation only
Fix from $1,950 2024-09-23
Online Eyewear Shop CRITICAL 9.8
CVE-2024-9082

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functional…

No fix yet
Fix from $2,300 2024-09-22
Zitadel MEDIUM 6.5
CVE-2024-47060

Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively thei…

Fix: 2.54.10 / 2.55.8+
Fix from $1,600 2024-09-20
Youtrack MEDIUM 5.3
CVE-2024-47160

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

Fix: 2024.3.44799+
Fix from $1,600 2024-09-19
Xcode HIGH 7.8
CVE-2024-44162

This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain …

Fix: 16.0+
Fix from $1,950 2024-09-17
macOS MEDIUM 5.5
CVE-2024-40843

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to modify protected parts of the file syste…

Fix: 15.0+
Fix from $1,600 2024-09-17
macOS HIGH 7.5
CVE-2024-40770

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privileged user may be able to modify …

Fix: 15.0+
Fix from $1,950 2024-09-17
GitLab CRITICAL 9.1
CVE-2024-2743

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacke…

Fix: 17.1.7 / 17.2.5+
Fix from $2,300 2024-09-12
Pan Os HIGH 7.1
CVE-2024-8691

A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate…

Fix: 9.1.17 / 10.1.11+
Fix from $1,950 2024-09-11
Cmc MEDIUM 5.0
CVE-2024-4465

An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with…

Fix: 24.2.0+
Fix from $1,600 2024-09-11
Unclassified HIGH 8.0
CVE-2024-44667

Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unaut…

Mitigation only
Fix from $1,950 2024-09-10