Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Pulsar MEDIUM 6.4
CVE-2024-29834

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as u…

Fix: 3.0.4 / 3.2.2+
Fix from $1,600 2024-04-02
Teamcity MEDIUM 6.5
CVE-2024-31134

In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was dis…

Fix: 2024.03+
Fix from $1,600 2024-03-28
Elasticsearch MEDIUM 6.5
CVE-2024-23451

Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.…

Fix: 8.13.0+
Fix from $1,600 2024-03-27
Unclassified HIGH 7.4
CVE-2023-6400

Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of Device Resources.This issue aff…

Mitigation only
Fix from $1,950 2024-03-27
Devolutions Server HIGH 8.8
CVE-2024-2915

Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation featu…

Fix: 2024.1.8.0+
Fix from $1,950 2024-03-26
Deno HIGH 8.8
CVE-2024-27933

Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ipc_pipe()` leads to premature …

Patch available
Fix from $1,950 2024-03-21
Frappe MEDIUM 6.5
CVE-2024-27105

Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, gra…

Fix: 14.66.3 / 15.16.0+
Fix from $1,600 2024-03-21
School Fees Management System HIGH 8.8
CVE-2023-49982

Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perf…

No fix yet
Fix from $1,950 2024-03-21
Visual Access Manager MEDIUM 6.5
CVE-2023-50811

An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific …

Mitigation only
Fix from $1,600 2024-03-19
Unclassified CRITICAL 9.8
CVE-2024-28394

An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistic…

Mitigation only
Fix from $2,300 2024-03-19
Food Waste Management System CRITICAL 9.1
CVE-2024-2557

A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of…

No fix yet
Fix from $2,300 2024-03-17
Legal Pages HIGH 8.0
CVE-2023-50886

Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.3.7.

Fix: 1.3.8+
Fix from $1,950 2024-03-15
Vantage6 MEDIUM 6.5
CVE-2024-23823

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Comput…

Fix: 4.2.1+
Fix from $1,600 2024-03-14
Argo Cd MEDIUM 6.4
CVE-2023-50726

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily ov…

Fix: 2.8.12 / 2.9.7+
Fix from $1,600 2024-03-13
Wp Show Posts MEDIUM 5.3
CVE-2024-1479

The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the wpsp_displ…

Fix: 1.1.5+
Fix from $1,600 2024-03-13
Pulsar MEDIUM 5.4
CVE-2024-28098

The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and off…

Fix: 2.10.6 / 2.11.4+
Fix from $1,600 2024-03-12
Siveillance Control MEDIUM 5.5
CVE-2023-45793

A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check the list of …

Fix: 3.1.1+
Fix from $1,600 2024-03-12
Fiori Front End Server MEDIUM 6.5
CVE-2024-22133

SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This cou…

Mitigation only
Fix from $1,600 2024-03-12
Ipad Os MEDIUM 5.5
CVE-2024-23250

An access issue was addressed with improved access restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watch…

Fix: 10.4 / 14.4+
Fix from $1,600 2024-03-08
Youtrack MEDIUM 6.5
CVE-2024-28229

In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

Fix: 2024.1.25893+
Fix from $1,600 2024-03-07
GitLab HIGH 8.0
CVE-2024-0199

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 1…

Fix: 16.7.7 / 16.8.4+
Fix from $1,950 2024-03-07
Sulu HIGH 8.1
CVE-2024-27915

Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of ro…

Fix: 2.4.17 / 2.5.13+
Fix from $1,950 2024-03-06
Galette HIGH 7.5
CVE-2024-24761

Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages a…

Patch available
Fix from $1,950 2024-03-06
Teamcity MEDIUM 5.8
CVE-2024-28174

In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly

Fix: 2023.11.4+
Fix from $1,600 2024-03-06
Archiva HIGH 7.5
CVE-2024-27139

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated…

Mitigation only
Fix from $1,950 2024-03-01
Archiva HIGH 7.5
CVE-2024-27138

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, …

Mitigation only
Fix from $1,950 2024-03-01
Cp4ba Filenet Content Manager HIGH 8.8
CVE-2023-47716

IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual…

Mitigation only
Fix from $1,950 2024-03-01
Nx Os MEDIUM 5.8
CVE-2024-20291

A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalon…

Mitigation only
Fix from $1,600 2024-02-29
Mezzanine CRITICAL 9.1
CVE-2024-25170

An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.

No fix yet
Fix from $2,300 2024-02-28
Superset MEDIUM 6.5
CVE-2024-24773

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apa…

Fix: 3.0.4 / 3.1.1+
Fix from $1,600 2024-02-28