Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.5 CVE-2024-34130 Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Securit… Acrobat Reader 24.5.0.33694+ Fix from $1,6002024-06-13 MEDIUM 5.3 CVE-2024-34106 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in… Commerce after 1.4.0 Fix from $1,6002024-06-13 HIGH 7.5 CVE-2024-2098 The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLib… Download Manager 3.2.90+ Fix from $1,9502024-06-13 HIGH 8.1 CVE-2024-37300 OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusO… Patch available Fix from $1,9502024-06-12 CRITICAL 9.8 CVE-2024-36265 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Co… Submarine Mitigation only Fix from $2,3002024-06-12 HIGH 8.8 CVE-2024-2698 A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardabl… Freeipa 4.11.2+ Fix from $1,9502024-06-12 MEDIUM 6.8 CVE-2024-0160 Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this… Xps 17 9700 Firmware 1.28.0 / 1.29.0+ Fix from $1,6002024-06-12 MEDIUM 5.4 CVE-2024-31403 Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo. Garoon 6.0.1+ Fix from $1,6002024-06-11 MEDIUM 5.3 CVE-2024-2473 The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypas… Wps Hide Login 1.9.16+ Fix from $1,6002024-06-11 HIGH 7.8 CVE-2024-27848 This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may … Ipados 14.5 / 17.5+ Fix from $1,9502024-06-10 MEDIUM 6.5 CVE-2022-45168 An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code end… Vdesk after 018 Fix from $1,6002024-06-10 CRITICAL 9.8 CVE-2024-4146 In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects… Lunary Patch available Fix from $2,3002024-06-08 MEDIUM 6.5 CVE-2024-3404 In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. T… Chuanhuchatgpt 20240919-4+ Fix from $1,6002024-06-06 MEDIUM 5.3 CVE-2024-37154 Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects … Evmos Mitigation only Fix from $1,6002024-06-06 CRITICAL 9.4 CVE-2024-3033 An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-… Anythingllm 1.0.0+ Fix from $2,3002024-06-06 MEDIUM 6.5 CVE-2024-3504 An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization us… Lunary 1.2.7+ Fix from $1,6002024-06-06 HIGH 8.8 CVE-2024-5324 Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check o… Login\/signup Popup 2.6.1 / 2.6.2+ Fix from $1,9502024-06-06 HIGH 8.8 CVE-2024-23669 An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug… Fortiwebmanager 6.2.5 / 7.0.5+ Fix from $1,9502024-06-05 CRITICAL 9.8 CVE-2024-31682 Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint au… Mitigation only Fix from $2,3002024-06-03 HIGH 7.5 CVE-2024-32983 Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming sign… Misskey 2024.5.0+ Fix from $1,9502024-06-03 HIGH 7.8 CVE-2024-36963 In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permissions are options There's an inc… Linux Kernel 6.6.31 / 6.8.10+ Fix from $1,9502024-06-03 CRITICAL 9.8 CVE-2024-35353 A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /cla… Dino Physics School Assistant No fix yet Fix from $2,3002024-05-30 HIGH 8.1 CVE-2024-36376 In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions Teamcity 2024.03.2+ Fix from $1,9502024-05-29 HIGH 8.1 CVE-2024-36377 In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions Teamcity 2024.03.2+ Fix from $1,9502024-05-29 MEDIUM 6.5 CVE-2024-36364 In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build fe… Teamcity 2022.04.7 / 2022.10.6+ Fix from $1,6002024-05-29 HIGH 8.1 CVE-2024-36365 In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent Teamcity 2022.04.7 / 2022.10.6+ Fix from $1,9502024-05-29 MEDIUM 5.5 CVE-2024-36037 Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings. Manageengine Adaudit Plus 7.2+ Fix from $1,6002024-05-27 MEDIUM 5.5 CVE-2024-36055 Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory with read/write access via t… Mitigation only Fix from $1,6002024-05-26 HIGH 8.1 CVE-2024-27312 Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. … Manageengine Pam360 6.6+ Fix from $1,9502024-05-20 HIGH 7.8 CVE-2024-3745 MSI Afterburner v4.6.6.16381 Beta 3 is vulnerable to an ACL Bypass vulnerability in the RTCore64.sys driver, which leads to triggering vulnerabilitie… Mitigation only Fix from $1,9502024-05-18