Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.1 CVE-2024-54662 Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod. Mitigation only Fix from $2,3002024-12-17 HIGH 7.5 CVE-2024-37775 Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check. Dctrack Mitigation only Fix from $1,9502024-12-16 MEDIUM 5.3 CVE-2024-8116 An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a s… GitLab 17.4.6 / 17.5.4+ Fix from $1,6002024-12-16 MEDIUM 5.3 CVE-2024-8650 An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed… GitLab 17.4.6 / 17.5.4+ Fix from $1,6002024-12-16 HIGH 8.8 CVE-2024-55662 XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extensio… Xwiki 15.10.9 / 16.3.0+ Fix from $1,9502024-12-12 MEDIUM 6.5 CVE-2024-55633 Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed… Superset 4.1.0+ Fix from $1,6002024-12-12 MEDIUM 5.5 CVE-2024-54495 The issue was addressed with improved permissions logic. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to modify… macOS 14.7.2 / 15.2+ Fix from $1,6002024-12-12 MEDIUM 6.5 CVE-2024-53949 Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users … Superset 4.1.0+ Fix from $1,6002024-12-09 HIGH 8.8 CVE-2024-55579 An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create … Mitigation only Fix from $1,9502024-12-09 MEDIUM 6.5 CVE-2024-12196 Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password hi… Devolutions Server 2024.3.8.0+ Fix from $1,6002024-12-04 MEDIUM 6.5 CVE-2024-42451 A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a s… Veeam Backup \& Replication 12.3.0.310+ Fix from $1,6002024-12-04 HIGH 8.8 CVE-2024-42452 A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectiv… Veeam Backup \& Replication 12.3.0.310+ Fix from $1,9502024-12-04 HIGH 8.1 CVE-2024-45106 Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t… Ozone Mitigation only Fix from $1,9502024-12-03 HIGH 8.8 CVE-2024-53937 An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by defau… Mitigation only Fix from $1,9502024-12-02 HIGH 8.8 CVE-2024-53941 An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote attacker (in proximity to a W… Mitigation only Fix from $1,9502024-12-02 CRITICAL 9.1 CVE-2024-52732 Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system being reused. Mitigation only Fix from $2,3002024-12-02 HIGH 7.5 CVE-2024-36611 In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where t… Patch available Fix from $1,9502024-11-29 HIGH 7.5 CVE-2024-48651 In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups… Patch available Fix from $1,9502024-11-29 HIGH 8.8 CVE-2024-54124 In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen. Mitigation only Fix from $1,9502024-11-29 HIGH 7.8 CVE-2018-9374 In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User… Android Patch available Fix from $1,9502024-11-28 HIGH 7.5 CVE-2024-11669 An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API end… GitLab 17.4.5 / 17.5.3+ Fix from $1,9502024-11-26 HIGH 7.8 CVE-2024-7915 The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform multiple operations as the ro… Mitigation only Fix from $1,9502024-11-25 MEDIUM 5.4 CVE-2024-11670 Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malici… Remote Desktop Manager after 2024.3.10.0 Fix from $1,6002024-11-25 MEDIUM 5.3 CVE-2024-11176 Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorre… Mitigation only Fix from $1,6002024-11-20 HIGH 7.8 CVE-2023-21270 In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to … Android Patch available Fix from $1,9502024-11-19 HIGH 7.5 CVE-2024-21287 KEV Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The suppor… Agile Product Lifecycle Management Mitigation only Fix from $1,9502024-11-18 MEDIUM 5.4 CVE-2024-52584 Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view… Autolab Patch available Fix from $1,6002024-11-18 MEDIUM 5.4 CVE-2024-52518 Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would b… Nextcloud Server 28.0.12 / 29.0.9+ Fix from $1,6002024-11-15 HIGH 7.5 CVE-2024-50647 The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access … Mitigation only Fix from $1,9502024-11-15 HIGH 7.5 CVE-2024-50650 python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by mod… Python Book No fix yet Fix from $1,9502024-11-15