Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2024-9623 An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting f… GitLab 17.2.9 / 17.3.5+ Fix from $1,6002024-10-10 MEDIUM 6.5 CVE-2024-45132 Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result… Commerce Mitigation only Fix from $1,6002024-10-10 MEDIUM 5.4 CVE-2024-45128 Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result… Commerce Mitigation only Fix from $1,6002024-10-10 MEDIUM 5.4 CVE-2024-45131 Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result… Commerce Mitigation only Fix from $1,6002024-10-10 MEDIUM 5.4 CVE-2024-7048 In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/… Open Webui No fix yet Fix from $1,6002024-10-10 CRITICAL 9.1 CVE-2024-45160 Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty… Mitigation only Fix from $2,3002024-10-09 MEDIUM 6.1 CVE-2024-38425 Information disclosure while sending implicit broadcast containing APP launch information. Wsa8835 Firmware Mitigation only Fix from $1,6002024-10-07 HIGH 8.1 CVE-2024-47183 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectI… Parse Server 6.5.9 / 7.3.0+ Fix from $1,9502024-10-04 MEDIUM 6.8 CVE-2024-47616 Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all persistent Pomerium applicati… Patch available Fix from $1,6002024-10-02 HIGH 7.8 CVE-2024-47560 RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes… Mitigation only Fix from $1,9502024-10-01 MEDIUM 5.4 CVE-2024-47172 Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may ret… Computer Vision Annotation Tool 2.19.1+ Fix from $1,6002024-09-30 MEDIUM 6.5 CVE-2024-47077 authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that… Authentik 2024.6.5 / 2024.8.3+ Fix from $1,6002024-09-27 HIGH 7.5 CVE-2024-9136 Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service co… Emui No fix yet Fix from $1,9502024-09-27 CRITICAL 9.8 CVE-2024-7108 Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by A… Cybermath Mitigation only Fix from $2,3002024-09-26 CRITICAL 9.3 CVE-2024-20510 A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adj… Ios Xe Mitigation only Fix from $2,3002024-09-25 CRITICAL 9.8 CVE-2024-47078 Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or p… Meshtastic Firmware 2.5.1+ Fix from $2,3002024-09-25 MEDIUM 6.5 CVE-2024-6512 Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permiss… Devolutions Server 2024.3.0+ Fix from $1,6002024-09-25 CRITICAL 9.1 CVE-2024-6592 An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Wi… Authentication Gateway after 12.10.2 Fix from $2,3002024-09-25 CRITICAL 9.1 CVE-2024-6593 Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network acce… Authentication Gateway after 12.10.2 Fix from $2,3002024-09-25 HIGH 8.8 CVE-2024-8606 Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication Checkmk Mitigation only Fix from $1,9502024-09-23 CRITICAL 9.8 CVE-2024-9082 A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functional… Online Eyewear Shop No fix yet Fix from $2,3002024-09-22 MEDIUM 6.5 CVE-2024-47060 Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively thei… Zitadel 2.54.10 / 2.55.8+ Fix from $1,6002024-09-20 MEDIUM 5.3 CVE-2024-47160 In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible Youtrack 2024.3.44799+ Fix from $1,6002024-09-19 HIGH 7.8 CVE-2024-44162 This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain … Xcode 16.0+ Fix from $1,9502024-09-17 MEDIUM 5.5 CVE-2024-40843 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to modify protected parts of the file syste… macOS 15.0+ Fix from $1,6002024-09-17 HIGH 7.5 CVE-2024-40770 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privileged user may be able to modify … macOS 15.0+ Fix from $1,9502024-09-17 CRITICAL 9.1 CVE-2024-2743 An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacke… GitLab 17.1.7 / 17.2.5+ Fix from $2,3002024-09-12 HIGH 7.1 CVE-2024-8691 A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate… Pan Os 9.1.17 / 10.1.11+ Fix from $1,9502024-09-11 MEDIUM 5.0 CVE-2024-4465 An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with… Cmc 24.2.0+ Fix from $1,6002024-09-11 HIGH 8.0 CVE-2024-44667 Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unaut… Mitigation only Fix from $1,9502024-09-10