Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Acrobat Reader MEDIUM 5.5
CVE-2024-34130

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Securit…

Fix: 24.5.0.33694+
Fix from $1,600 2024-06-13
Commerce MEDIUM 5.3
CVE-2024-34106

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in…

Fix: after 1.4.0
Fix from $1,600 2024-06-13
Download Manager HIGH 7.5
CVE-2024-2098

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLib…

Fix: 3.2.90+
Fix from $1,950 2024-06-13
Unclassified HIGH 8.1
CVE-2024-37300

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusO…

Patch available
Fix from $1,950 2024-06-12
Submarine CRITICAL 9.8
CVE-2024-36265

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Co…

Mitigation only
Fix from $2,300 2024-06-12
Freeipa HIGH 8.8
CVE-2024-2698

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardabl…

Fix: 4.11.2+
Fix from $1,950 2024-06-12
Xps 17 9700 Firmware MEDIUM 6.8
CVE-2024-0160

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this…

Fix: 1.28.0 / 1.29.0+
Fix from $1,600 2024-06-12
Garoon MEDIUM 5.4
CVE-2024-31403

Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.

Fix: 6.0.1+
Fix from $1,600 2024-06-11
Wps Hide Login MEDIUM 5.3
CVE-2024-2473

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypas…

Fix: 1.9.16+
Fix from $1,600 2024-06-11
Ipados HIGH 7.8
CVE-2024-27848

This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may …

Fix: 14.5 / 17.5+
Fix from $1,950 2024-06-10
Vdesk MEDIUM 6.5
CVE-2022-45168

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code end…

Fix: after 018
Fix from $1,600 2024-06-10
Lunary CRITICAL 9.8
CVE-2024-4146

In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects…

Patch available
Fix from $2,300 2024-06-08
Chuanhuchatgpt MEDIUM 6.5
CVE-2024-3404

In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. T…

Fix: 20240919-4+
Fix from $1,600 2024-06-06
Evmos MEDIUM 5.3
CVE-2024-37154

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects …

Mitigation only
Fix from $1,600 2024-06-06
Anythingllm CRITICAL 9.4
CVE-2024-3033

An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-…

Fix: 1.0.0+
Fix from $2,300 2024-06-06
Lunary MEDIUM 6.5
CVE-2024-3504

An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization us…

Fix: 1.2.7+
Fix from $1,600 2024-06-06
Login\/signup Popup HIGH 8.8
CVE-2024-5324

Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check o…

Fix: 2.6.1 / 2.6.2+
Fix from $1,950 2024-06-06
Fortiwebmanager HIGH 8.8
CVE-2024-23669

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…

Fix: 6.2.5 / 7.0.5+
Fix from $1,950 2024-06-05
Unclassified CRITICAL 9.8
CVE-2024-31682

Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint au…

Mitigation only
Fix from $2,300 2024-06-03
Misskey HIGH 7.5
CVE-2024-32983

Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming sign…

Fix: 2024.5.0+
Fix from $1,950 2024-06-03
Linux Kernel HIGH 7.8
CVE-2024-36963

In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permissions are options There's an inc…

Fix: 6.6.31 / 6.8.10+
Fix from $1,950 2024-06-03
Dino Physics School Assistant CRITICAL 9.8
CVE-2024-35353

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /cla…

No fix yet
Fix from $2,300 2024-05-30
Teamcity HIGH 8.1
CVE-2024-36376

In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions

Fix: 2024.03.2+
Fix from $1,950 2024-05-29
Teamcity HIGH 8.1
CVE-2024-36377

In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

Fix: 2024.03.2+
Fix from $1,950 2024-05-29
Teamcity MEDIUM 6.5
CVE-2024-36364

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build fe…

Fix: 2022.04.7 / 2022.10.6+
Fix from $1,600 2024-05-29
Teamcity HIGH 8.1
CVE-2024-36365

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent

Fix: 2022.04.7 / 2022.10.6+
Fix from $1,950 2024-05-29
Manageengine Adaudit Plus MEDIUM 5.5
CVE-2024-36037

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.

Fix: 7.2+
Fix from $1,600 2024-05-27
Unclassified MEDIUM 5.5
CVE-2024-36055

Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory with read/write access via t…

Mitigation only
Fix from $1,600 2024-05-26
Manageengine Pam360 HIGH 8.1
CVE-2024-27312

Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. …

Fix: 6.6+
Fix from $1,950 2024-05-20
Unclassified HIGH 7.8
CVE-2024-3745

MSI Afterburner v4.6.6.16381 Beta 3 is vulnerable to an ACL Bypass vulnerability in the RTCore64.sys driver, which leads to triggering vulnerabilitie…

Mitigation only
Fix from $1,950 2024-05-18