Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.8 CVE-2024-31695 A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication wh… Mitigation only Fix from $2,3002024-11-14 HIGH 8.1 CVE-2024-3379 In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key f… Lunary 1.2.7+ Fix from $1,9502024-11-14 HIGH 7.7 CVE-2022-31670 Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an i… Harbor 1.10.13 / 2.4.3+ Fix from $1,9502024-11-14 HIGH 7.4 CVE-2022-31671 Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request t… Harbor 2.4.3 / 2.5.2+ Fix from $1,9502024-11-14 MEDIUM 6.4 CVE-2022-31667 Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access… Harbor 2.4.3 / 2.5.2+ Fix from $1,6002024-11-14 HIGH 7.7 CVE-2022-31668 Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that… Harbor 2.4.3 / 2.5.2+ Fix from $1,9502024-11-14 HIGH 7.7 CVE-2022-31669 Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy wit… Harbor 2.4.3 / 2.5.2+ Fix from $1,9502024-11-14 HIGH 8.8 CVE-2024-9693 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting f… GitLab 17.3.7 / 17.4.4+ Fix from $1,9502024-11-14 MEDIUM 6.5 CVE-2024-45877 baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.asp… Mitigation only Fix from $1,6002024-11-13 HIGH 7.5 CVE-2024-50310 A vulnerability has been identified in SIMATIC CP 1543-1 V4.0 (6GK7543-1AX10-0XE0) (All versions >= V4.0.44 < V4.0.50). Affected devices do not prope… Simatic Cp 1543 1 Firmware 4.0.50+ Fix from $1,9502024-11-12 MEDIUM 5.3 CVE-2024-43433 A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users. Moodle 4.3.6 / 4.4.2+ Fix from $1,6002024-11-11 MEDIUM 5.4 CVE-2024-52312 Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations ag… Data.all 2.6.1+ Fix from $1,6002024-11-09 MEDIUM 6.5 CVE-2024-44765 An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users… Mitigation only Fix from $1,6002024-11-08 HIGH 7.7 CVE-2024-10975 Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized C… Nomad 1.7.15 / 1.8.7+ Fix from $1,9502024-11-07 MEDIUM 6.5 CVE-2024-20537 A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanis… Identity Services Engine Mitigation only Fix from $1,6002024-11-06 MEDIUM 6.3 CVE-2024-9902 A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on … Mitigation only Fix from $1,6002024-11-06 CRITICAL 9.8 CVE-2024-48176 Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not b… Lylme Spage Mitigation only Fix from $2,3002024-11-05 HIGH 8.8 CVE-2024-30616 Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, p… Chamilo Lms Patch available Fix from $1,9502024-11-04 HIGH 7.1 CVE-2024-45164 Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Po… Secure Internet Access Enterprise Threatavert No fix yet Fix from $1,9502024-11-04 HIGH 8.8 CVE-2024-49256 Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionality Not Properly Constrained b… Htaccess File Editor 1.0.19+ Fix from $1,9502024-11-01 MEDIUM 5.7 CVE-2024-49501 Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may ac… Mitigation only Fix from $1,6002024-11-01 HIGH 8.8 CVE-2024-51425 An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact. NOTE: … No fix yet Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51426 An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the _… No fix yet Fix from $1,9502024-10-30 CRITICAL 9.8 CVE-2024-50419 Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Acce… Greenshift Animation And Page Builder Blocks 9.8+ Fix from $2,3002024-10-30 CRITICAL 9.1 CVE-2024-44217 A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password aut… Ipados 18.0+ Fix from $2,3002024-10-28 MEDIUM 5.5 CVE-2024-44287 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious appli… macOS 13.7.1 / 14.7.1+ Fix from $1,6002024-10-28 HIGH 7.5 CVE-2024-44289 A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, m… macOS 13.7.1 / 14.7.1+ Fix from $1,9502024-10-28 MEDIUM 5.5 CVE-2024-44301 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious appli… macOS 13.7.1 / 14.7.1+ Fix from $1,6002024-10-28 HIGH 8.6 CVE-2024-44270 A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A sandbox… macOS 13.7.1 / 14.7.1+ Fix from $1,9502024-10-28 MEDIUM 5.5 CVE-2024-44247 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious appli… macOS 13.7.1 / 14.7.1+ Fix from $1,6002024-10-28