Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified CRITICAL 9.8
CVE-2024-6782EPSS 84%

Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.

Patch available
Fix from $2,300 2024-08-06
Unclassified HIGH 7.5
CVE-2024-40530

A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Fo…

Mitigation only
Fix from $1,950 2024-08-05
Ofbiz CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versi…

Fix: 18.12.15+
Fix from $2,300 2024-08-05
Caterease HIGH 7.8
CVE-2024-38884

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform …

Fix: after 24.0.1.2405
Fix from $1,950 2024-08-02
Profile Builder CRITICAL 9.8
CVE-2024-6695

it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions.…

Fix: 3.11.9+
Fix from $2,300 2024-07-31
Unclassified HIGH 7.5
CVE-2024-41670

In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a maliciou…

Mitigation only
Fix from $1,950 2024-07-26
Nimble Commander HIGH 7.8
CVE-2024-7062

Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improp…

Fix: 1.6.1+
Fix from $1,950 2024-07-26
Unclassified CRITICAL 9.9
CVE-2024-4447

In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSess…

Mitigation only
Fix from $2,300 2024-07-26
Fabedge CRITICAL 9.8
CVE-2024-36536

Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Mitigation only
Fix from $2,300 2024-07-24
Unclassified CRITICAL 9.9
CVE-2024-41110EPSS 16%

Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Doc…

Patch available
Fix from $2,300 2024-07-24
Sdg Smartos HIGH 8.8
CVE-2024-31970

AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LA…

Fix: 12.1.3.1+
Fix from $1,950 2024-07-24
Enterprise Asset Management HIGH 8.1
CVE-2024-21149

Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues). Supported versions t…

Fix: after 12.2.13
Fix from $1,950 2024-07-16
Enterprise Server MEDIUM 5.3
CVE-2024-5816

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repos…

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Enterprise Server MEDIUM 6.5
CVE-2024-5817

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. Th…

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Unclassified MEDIUM 5.3
CVE-2024-39905

Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_channel()` command permission chec…

Patch available
Fix from $1,600 2024-07-11
Sinema Remote Connect Server MEDIUM 5.4
CVE-2024-39871

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rig…

Fix: 3.2+
Fix from $1,600 2024-07-09
Evmos HIGH 8.1
CVE-2024-39696

Evmos is a decentralized Ethereum Virtual Machine chain on the Cosmos Network. Prior to version 19.0.0, a user can create a vesting account with a 3r…

Fix: 19.0.0+
Fix from $1,950 2024-07-05
Himer MEDIUM 6.5
CVE-2024-2231

The allows any authenticated user to join a private group due to a missing authorization check on a function

Fix: 2.1.1+
Fix from $1,600 2024-07-03
Ai Controller Frontend MEDIUM 5.5
CVE-2024-39322

aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4,…

Fix: 2020.10.13 / 2021.10.6+
Fix from $1,600 2024-07-02
Unclassified HIGH 7.1
CVE-2024-39323

aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 20…

Patch available
Fix from $1,950 2024-07-02
Authentik HIGH 8.8
CVE-2024-37905

authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to g…

Fix: 2024.2.4 / 2024.4.3+
Fix from $1,950 2024-06-28
Unclassified MEDIUM 6.8
CVE-2024-3331

Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotf…

No fix yet
Fix from $1,600 2024-06-27
Lunary MEDIUM 6.8
CVE-2024-5714

In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissions to manipulate project ide…

Patch available
Fix from $1,600 2024-06-27
Security Access Manager MEDIUM 5.5
CVE-2023-38368

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls.…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-27
GitLab HIGH 7.5
CVE-2024-6323

Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17…

Fix: 16.11.5 / 17.0.3+
Fix from $1,950 2024-06-27
Bookster MEDIUM 6.5
CVE-2024-5071

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the dat…

Fix: after 1.1.0
Fix from $1,600 2024-06-26
Jupiter X Core CRITICAL 9.8
CVE-2023-38389

Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Jup…

Fix: after 3.3.8
Fix from $2,300 2024-06-21
License Manager For Woocommerce MEDIUM 6.5
CVE-2024-1639

The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLi…

Fix: after 3.0.7
Fix from $1,600 2024-06-21
Depicter MEDIUM 6.5
CVE-2024-4390

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0…

Fix: 3.1.0+
Fix from $1,600 2024-06-20
Storage Protect For Virtual Environments HIGH 7.7
CVE-2024-38329

IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypa…

Fix: 8.1.23.0+
Fix from $1,950 2024-06-19