Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.1 CVE-2024-42423 Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogi… Workspace Mitigation only Fix from $1,9502024-09-10 HIGH 7.5 CVE-2024-6979 Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or view… Axis Os 2024 11.11.94+ Fix from $1,9502024-09-10 MEDIUM 6.5 CVE-2024-8601 This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An auth… Back Office Software 1.0.0+ Fix from $1,6002024-09-09 MEDIUM 5.5 CVE-2024-34651 Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files. Android Mitigation only Fix from $1,6002024-09-04 HIGH 8.1 CVE-2024-45588 This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Preference module … Xts Mobile Trader Mitigation only Fix from $1,9502024-09-03 HIGH 8.8 CVE-2024-45586 This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platfor… Xts Mobile Trader Mitigation only Fix from $1,9502024-09-03 HIGH 8.8 CVE-2024-45587 This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module… Xts Mobile Trader Mitigation only Fix from $1,9502024-09-03 MEDIUM 6.5 CVE-2024-45509 In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not… Misp 2.4.197+ Fix from $1,6002024-09-01 HIGH 8.3 CVE-2024-38868 Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Cent… Manageengine Endpoint Central 11.3.2400.15 / 11.3.2406.08+ Fix from $1,9502024-08-30 HIGH 8.1 CVE-2024-41964 Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform … Kirby 3.6.6.6 / 3.7.5.5+ Fix from $1,9502024-08-29 MEDIUM 6.3 CVE-2024-43954 Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Droip: from… Droip after 1.1.1 Fix from $1,6002024-08-29 MEDIUM 5.3 CVE-2024-45043 The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream messages and parsing the records … Patch available Fix from $1,6002024-08-28 MEDIUM 6.4 CVE-2024-45037 The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own ap… Aws Cloud Development Kit 2.148.1+ Fix from $1,6002024-08-27 MEDIUM 5.5 CVE-2024-8011 Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the … Options\+ 1.72+ Fix from $1,6002024-08-25 MEDIUM 5.4 CVE-2024-38869 Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects En… Manageengine Servicedesk Plus after 14.7 Fix from $1,6002024-08-23 CRITICAL 9.1 CVE-2024-42773 An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an una… Hotel Management System No fix yet Fix from $2,3002024-08-22 HIGH 7.8 CVE-2024-7604 Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability. This vulnerability allows local attackers to bypass auth… Unified Secops Platform Mitigation only Fix from $1,9502024-08-21 MEDIUM 6.5 CVE-2024-6337 An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_reques… Enterprise Server 3.10.16 / 3.11.14+ Fix from $1,6002024-08-20 HIGH 8.8 CVE-2024-31842 An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The quer… Embrace Mitigation only Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-39690 Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespa… Capsule after 0.7.0 Fix from $1,9502024-08-20 MEDIUM 6.5 CVE-2024-43250 Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue … Bit Form after 2.6.4 Fix from $1,6002024-08-19 CRITICAL 9.8 CVE-2024-42966 Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the userna… N350rt Firmware No fix yet Fix from $2,3002024-08-15 HIGH 8.1 CVE-2024-7624 The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is … Zephyr Project Manager 3.3.102+ Fix from $1,9502024-08-15 HIGH 7.5 CVE-2024-43131 Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Co… Docket 1.7.0+ Fix from $1,9502024-08-13 HIGH 8.8 CVE-2024-41939 A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This… Sinec Nms 3.0+ Fix from $1,9502024-08-13 CRITICAL 9.8 CVE-2024-42473 OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model t… Openfga Mitigation only Fix from $2,3002024-08-12 HIGH 8.8 CVE-2024-7265 Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change… Ezd Rp 15.84 / 16.15+ Fix from $1,9502024-08-07 HIGH 7.2 CVE-2024-42062 CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register ran… Cloudstack 4.18.2.3 / 4.19.1.1+ Fix from $1,9502024-08-07 HIGH 8.8 CVE-2024-6358 Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence. Arcsight Intelligence 6.4.13+ Fix from $1,9502024-08-06 CRITICAL 9.8 CVE-2024-6202 HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymo… Haloitsm 2.143.61 / 2.146.1+ Fix from $2,3002024-08-06