Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2024-57678 An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and… Dir 816 Firmware Mitigation only Fix from $1,6002025-01-16 MEDIUM 6.5 CVE-2024-57679 An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the… Dir 816 Firmware Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.3 CVE-2024-57680 An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set th… Dir 816 Firmware Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.3 CVE-2024-57681 An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl servi… Dir 816 Firmware Mitigation only Fix from $1,6002025-01-16 MEDIUM 6.5 CVE-2024-57676 An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set th… Dir 816 Firmware Mitigation only Fix from $1,6002025-01-16 HIGH 7.8 CVE-2024-40771 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey … Ipados 1.2 / 12.7.5+ Fix from $1,9502025-01-15 MEDIUM 6.4 CVE-2025-21403 On-Premises Data Gateway Information Disclosure Vulnerability On Prem Data Gateway 3000.246+ Fix from $1,6002025-01-14 MEDIUM 5.3 CVE-2024-13302 Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2… Pages Restriction Access 2.0.3+ Fix from $1,6002025-01-09 MEDIUM 5.3 CVE-2024-13290 Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before … Ohdear Integration 2.0.4+ Fix from $1,6002025-01-09 HIGH 7.3 CVE-2024-13291 Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from… Basic Http Authentication 7.x-1.4+ Fix from $1,9502025-01-09 MEDIUM 6.5 CVE-2024-56114 Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improp… Canlineapp No fix yet Fix from $1,6002025-01-09 CRITICAL 9.1 CVE-2024-13281 Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2. Monster Menus 7.x-1.34 / 9.3.2+ Fix from $2,3002025-01-09 HIGH 8.8 CVE-2024-13282 Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.… Block Permissions 1.2.0+ Fix from $1,9502025-01-09 CRITICAL 9.1 CVE-2024-13277 Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1. Smart Ip Ban 7.x-1.1+ Fix from $2,3002025-01-09 CRITICAL 9.1 CVE-2024-13278 Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0. Diff 1.8.0+ Fix from $2,3002025-01-09 MEDIUM 5.3 CVE-2024-13266 Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas … Responsive And Off Canvas Menu 4.4.4+ Fix from $1,6002025-01-09 CRITICAL 9.1 CVE-2024-13253 Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push… Advanced Pwa Inc Push Notifications 8.x-1.5+ Fix from $2,3002025-01-09 MEDIUM 5.3 CVE-2024-13257 Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 b… Commerce View Receipt 1.0.3+ Fix from $1,6002025-01-09 CRITICAL 9.8 CVE-2024-13258 Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON … Rest \& Json Api Authentication 2.0.13+ Fix from $2,3002025-01-09 MEDIUM 5.4 CVE-2025-0237 The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the prin… Firefox 128.6.0 / 134.0+ Fix from $1,6002025-01-07 HIGH 7.5 CVE-2024-39025 Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data. Mitigation only Fix from $1,9502024-12-27 MEDIUM 6.8 CVE-2020-9081 There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to expl… Mate 20 Firmware 10.1.0.88 / 10.1.0.160+ Fix from $1,6002024-12-27 MEDIUM 5.5 CVE-2024-47148 Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. Magicos 8.0.0.112+ Fix from $1,6002024-12-26 MEDIUM 5.5 CVE-2024-47157 Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. Magicos 8.0.0.135+ Fix from $1,6002024-12-26 CRITICAL 9.8 CVE-2024-56431 oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parti… Theora 1.2.0+ Fix from $2,3002024-12-25 MEDIUM 5.5 CVE-2024-47102 IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause… Vios Mitigation only Fix from $1,6002024-12-25 HIGH 7.8 CVE-2024-12831 Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privil… Ng Firewall Mitigation only Fix from $1,9502024-12-20 CRITICAL 10.0 CVE-2023-4617 Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owne… Mitigation only Fix from $2,3002024-12-19 MEDIUM 6.5 CVE-2024-12539 An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Leve… Elasticsearch 8.16.2+ Fix from $1,6002024-12-17 HIGH 7.5 CVE-2024-51479 Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in m… Next.js 14.2.15+ Fix from $1,9502024-12-17