Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Wordpress Meta Data And Taxonomies Filter MEDIUM 6.5
CVE-2024-34434

Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This…

Fix: 1.3.3.3+
Fix from $1,600 2024-05-17
Unclassified CRITICAL 9.1
CVE-2024-35187

Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user…

Mitigation only
Fix from $2,300 2024-05-16
Powerpanel HIGH 7.5
CVE-2024-31409

Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the sy…

Fix: after 4.9.0
Fix from $1,950 2024-05-15
Unclassified MEDIUM 5.4
CVE-2024-3722

The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function…

Mitigation only
Fix from $1,600 2024-05-14
Unclassified MEDIUM 5.9
CVE-2024-34701

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered as the requester of a specifi…

Patch available
Fix from $1,600 2024-05-14
Dataease HIGH 7.5
CVE-2024-31441

DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data sou…

Fix: 1.18.19+
Fix from $1,950 2024-05-14
macOS HIGH 7.8
CVE-2024-27798

An authorization issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 1…

Fix: 12.7.5 / 13.6.7+
Fix from $1,950 2024-05-14
Deno CRITICAL 9.0
CVE-2024-34346

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/w…

Fix: 1.43.1+
Fix from $2,300 2024-05-07
Android HIGH 7.8
CVE-2024-0043

In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code. This c…

Patch available
Fix from $1,950 2024-05-07
Premium Security HIGH 7.8
CVE-2023-42124

Avast Premium Security Sandbox Protection Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to es…

Mitigation only
Fix from $1,950 2024-05-03
Booster For Woocommerce HIGH 7.3
CVE-2024-3957

The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allow…

Fix: 7.1.9+
Fix from $1,950 2024-05-02
Print Labels With Barcodes HIGH 8.8
CVE-2024-1677

The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized ac…

Fix: 3.4.7+
Fix from $1,950 2024-05-02
Git Server MEDIUM 6.5
CVE-2024-34146

Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing a…

Fix: after 114.v068a_c7cc2574
Fix from $1,600 2024-05-02
Unclassified HIGH 8.0
CVE-2024-2378

A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privileges on af-fected installatio…

No fix yet
Fix from $1,950 2024-04-30
Qts HIGH 8.1
CVE-2023-50363

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…

Mitigation only
Fix from $1,950 2024-04-26
Bookingpress CRITICAL 9.8
CVE-2023-51405

Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…

Fix: 1.0.75+
Fix from $2,300 2024-04-24
Unclassified HIGH 7.5
CVE-2024-28627

An issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file.

Mitigation only
Fix from $1,950 2024-04-23
Tolgee MEDIUM 6.5
CVE-2024-32470

Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission check at all. This error was in…

Fix: 3.57.4+
Fix from $1,600 2024-04-18
Openfga CRITICAL 9.8
CVE-2024-31452

OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization…

Fix: 1.5.3+
Fix from $2,300 2024-04-16
Outside In Technology MEDIUM 5.3
CVE-2024-21120

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affe…

Mitigation only
Fix from $1,600 2024-04-16
Bi Publisher HIGH 7.2
CVE-2024-21083

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Script Engine). Supported versions that are affected are 7.0.0.0.0 …

Mitigation only
Fix from $1,950 2024-04-16
Hospitality Simphony CRITICAL 9.9
CVE-2024-21010

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported…

Fix: after 19.5.4
Fix from $2,300 2024-04-16
Lunary HIGH 7.5
CVE-2024-1738

An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations …

Fix: 1.2.4+
Fix from $1,950 2024-04-16
Argo Cd MEDIUM 6.3
CVE-2024-31990

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attac…

Fix: 2.8.16 / 2.9.12+
Fix from $1,600 2024-04-15
Smart Forms MEDIUM 6.5
CVE-2024-1307

The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a s…

Fix: 2.6.94+
Fix from $1,600 2024-04-15
Kafka HIGH 7.4
CVE-2024-27309

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditi…

Fix: after 3.6.1
Fix from $1,950 2024-04-12
Pan Os MEDIUM 5.0
CVE-2024-3388

A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and …

Fix: 8.1.26 / 9.0.17+
Fix from $1,600 2024-04-10
Lunary CRITICAL 9.1
CVE-2024-1740

In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs b…

Fix: 1.2.7+
Fix from $2,300 2024-04-10
Lunary CRITICAL 9.1
CVE-2024-1741

lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates…

Fix: 1.2.8+
Fix from $2,300 2024-04-10
Emui CRITICAL 9.1
CVE-2023-52538

Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect avai…

No fix yet
Fix from $2,300 2024-04-08