Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.5 CVE-2024-44253 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be abl… macOS 13.7.1 / 14.7.1+ Fix from $1,6002024-10-28 MEDIUM 5.5 CVE-2024-44196 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1.… macOS 13.7.1 / 14.7.1+ Fix from $1,6002024-10-28 MEDIUM 5.5 CVE-2024-40855 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2. A sandb… macOS 13.7.1 / 14.7.1+ Fix from $1,6002024-10-28 MEDIUM 5.4 CVE-2024-9825 The Chef Habitat builder-api on-prem-builder package  with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect … Mitigation only Fix from $1,6002024-10-28 MEDIUM 5.0 CVE-2024-48936 SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute process… Slurm 24.05.4+ Fix from $1,6002024-10-28 CRITICAL 9.8 CVE-2024-48237 WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php. Wtcms No fix yet Fix from $2,3002024-10-25 HIGH 8.8 CVE-2022-30358 OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw pa… Ovaledge after 5.2.8 Fix from $1,9502024-10-25 HIGH 8.8 CVE-2024-49376 Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0.… Autolab Patch available Fix from $1,9502024-10-25 MEDIUM 5.5 CVE-2024-47025 In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information di… Android Mitigation only Fix from $1,6002024-10-25 MEDIUM 5.5 CVE-2024-44099 There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additi… Android No fix yet Fix from $1,6002024-10-25 CRITICAL 9.8 CVE-2024-41617 Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions… Patch available Fix from $2,3002024-10-24 HIGH 8.0 CVE-2024-45261 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific use… Mt2500 Firmware 4.6.4+ Fix from $1,9502024-10-24 HIGH 8.0 CVE-2024-45260 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized gro… Mt6000 Firmware 4.6.4+ Fix from $1,9502024-10-24 HIGH 7.5 CVE-2024-10295 A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal… 3scale Api Management Mitigation only Fix from $1,9502024-10-24 HIGH 8.4 CVE-2024-48541 Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to access sensitive information by an… Mitigation only Fix from $1,9502024-10-24 HIGH 8.4 CVE-2024-48542 Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive in… Mitigation only Fix from $1,9502024-10-24 HIGH 8.4 CVE-2024-48544 Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information… Mitigation only Fix from $1,9502024-10-24 HIGH 8.4 CVE-2024-48545 Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyz… Mitigation only Fix from $1,9502024-10-24 HIGH 8.4 CVE-2024-48546 Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyz… Mitigation only Fix from $1,9502024-10-24 HIGH 8.4 CVE-2024-48547 Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information b… Mitigation only Fix from $1,9502024-10-24 CRITICAL 9.3 CVE-2024-48548 The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows attackers to … Mitigation only Fix from $2,3002024-10-24 MEDIUM 6.2 CVE-2024-48540 Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file. Mitigation only Fix from $1,6002024-10-24 MEDIUM 6.5 CVE-2024-20482 A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center… Secure Firewall Management Center Mitigation only Fix from $1,6002024-10-23 MEDIUM 6.5 CVE-2024-48925 Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version … Umbraco Cms 14.3.0+ Fix from $1,6002024-10-22 HIGH 8.8 CVE-2024-38002 The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th… Digital Experience Platform 7.4.3.112 / 2023.q3.9+ Fix from $1,9502024-10-22 HIGH 7.5 CVE-2024-10173 A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the compone… Ddmq No fix yet Fix from $1,9502024-10-20 HIGH 7.8 CVE-2024-29213 Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified … Desktop \& Server Management 2024.2+ Fix from $1,9502024-10-18 HIGH 7.8 CVE-2024-29821 Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified … Desktop \& Server Management 2024.2+ Fix from $1,9502024-10-18 HIGH 8.8 CVE-2024-20420 A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote … Ata 191 Firmware 11.2.5 / 12.0.2+ Fix from $1,9502024-10-16 CRITICAL 9.8 CVE-2024-45216EPSS 91% Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen… Solr 8.11.4 / 9.7.0+ Fix from $2,3002024-10-16