Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Workspace HIGH 7.1
CVE-2024-42423

Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogi…

Mitigation only
Fix from $1,950 2024-09-10
Axis Os 2024 HIGH 7.5
CVE-2024-6979

Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or view…

Fix: 11.11.94+
Fix from $1,950 2024-09-10
Back Office Software MEDIUM 6.5
CVE-2024-8601

This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An auth…

Fix: 1.0.0+
Fix from $1,600 2024-09-09
Android MEDIUM 5.5
CVE-2024-34651

Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

Mitigation only
Fix from $1,600 2024-09-04
Xts Mobile Trader HIGH 8.1
CVE-2024-45588

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Preference module …

Mitigation only
Fix from $1,950 2024-09-03
Xts Mobile Trader HIGH 8.8
CVE-2024-45586

This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platfor…

Mitigation only
Fix from $1,950 2024-09-03
Xts Mobile Trader HIGH 8.8
CVE-2024-45587

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module…

Mitigation only
Fix from $1,950 2024-09-03
Misp MEDIUM 6.5
CVE-2024-45509

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not…

Fix: 2.4.197+
Fix from $1,600 2024-09-01
Manageengine Endpoint Central HIGH 8.3
CVE-2024-38868

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Cent…

Fix: 11.3.2400.15 / 11.3.2406.08+
Fix from $1,950 2024-08-30
Kirby HIGH 8.1
CVE-2024-41964

Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform …

Fix: 3.6.6.6 / 3.7.5.5+
Fix from $1,950 2024-08-29
Droip MEDIUM 6.3
CVE-2024-43954

Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Droip: from…

Fix: after 1.1.1
Fix from $1,600 2024-08-29
Unclassified MEDIUM 5.3
CVE-2024-45043

The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream messages and parsing the records …

Patch available
Fix from $1,600 2024-08-28
Aws Cloud Development Kit MEDIUM 6.4
CVE-2024-45037

The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own ap…

Fix: 2.148.1+
Fix from $1,600 2024-08-27
Options\+ MEDIUM 5.5
CVE-2024-8011

Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the …

Fix: 1.72+
Fix from $1,600 2024-08-25
Manageengine Servicedesk Plus MEDIUM 5.4
CVE-2024-38869

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects En…

Fix: after 14.7
Fix from $1,600 2024-08-23
Hotel Management System CRITICAL 9.1
CVE-2024-42773

An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an una…

No fix yet
Fix from $2,300 2024-08-22
Unified Secops Platform HIGH 7.8
CVE-2024-7604

Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability. This vulnerability allows local attackers to bypass auth…

Mitigation only
Fix from $1,950 2024-08-21
Enterprise Server MEDIUM 6.5
CVE-2024-6337

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_reques…

Fix: 3.10.16 / 3.11.14+
Fix from $1,600 2024-08-20
Embrace HIGH 8.8
CVE-2024-31842

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The quer…

Mitigation only
Fix from $1,950 2024-08-20
Capsule HIGH 8.8
CVE-2024-39690

Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespa…

Fix: after 0.7.0
Fix from $1,950 2024-08-20
Bit Form MEDIUM 6.5
CVE-2024-43250

Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue …

Fix: after 2.6.4
Fix from $1,600 2024-08-19
N350rt Firmware CRITICAL 9.8
CVE-2024-42966

Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the userna…

No fix yet
Fix from $2,300 2024-08-15
Zephyr Project Manager HIGH 8.1
CVE-2024-7624

The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is …

Fix: 3.3.102+
Fix from $1,950 2024-08-15
Docket HIGH 7.5
CVE-2024-43131

Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Co…

Fix: 1.7.0+
Fix from $1,950 2024-08-13
Sinec Nms HIGH 8.8
CVE-2024-41939

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This…

Fix: 3.0+
Fix from $1,950 2024-08-13
Openfga CRITICAL 9.8
CVE-2024-42473

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model t…

Mitigation only
Fix from $2,300 2024-08-12
Ezd Rp HIGH 8.8
CVE-2024-7265

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change…

Fix: 15.84 / 16.15+
Fix from $1,950 2024-08-07
Cloudstack HIGH 7.2
CVE-2024-42062

CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register ran…

Fix: 4.18.2.3 / 4.19.1.1+
Fix from $1,950 2024-08-07
Arcsight Intelligence HIGH 8.8
CVE-2024-6358

Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.

Fix: 6.4.13+
Fix from $1,950 2024-08-06
Haloitsm CRITICAL 9.8
CVE-2024-6202

HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymo…

Fix: 2.143.61 / 2.146.1+
Fix from $2,300 2024-08-06