Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2024-34434 Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This… Wordpress Meta Data And Taxonomies Filter 1.3.3.3+ Fix from $1,6002024-05-17 CRITICAL 9.1 CVE-2024-35187 Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user… Mitigation only Fix from $2,3002024-05-16 HIGH 7.5 CVE-2024-31409 Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the sy… Powerpanel after 4.9.0 Fix from $1,9502024-05-15 MEDIUM 5.4 CVE-2024-3722 The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function… Mitigation only Fix from $1,6002024-05-14 MEDIUM 5.9 CVE-2024-34701 CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered as the requester of a specifi… Patch available Fix from $1,6002024-05-14 HIGH 7.5 CVE-2024-31441 DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data sou… Dataease 1.18.19+ Fix from $1,9502024-05-14 HIGH 7.8 CVE-2024-27798 An authorization issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 1… macOS 12.7.5 / 13.6.7+ Fix from $1,9502024-05-14 CRITICAL 9.0 CVE-2024-34346 Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/w… Deno 1.43.1+ Fix from $2,3002024-05-07 HIGH 7.8 CVE-2024-0043 In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code. This c… Android Patch available Fix from $1,9502024-05-07 HIGH 7.8 CVE-2023-42124 Avast Premium Security Sandbox Protection Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to es… Premium Security Mitigation only Fix from $1,9502024-05-03 HIGH 7.3 CVE-2024-3957 The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allow… Booster For Woocommerce 7.1.9+ Fix from $1,9502024-05-02 HIGH 8.8 CVE-2024-1677 The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized ac… Print Labels With Barcodes 3.4.7+ Fix from $1,9502024-05-02 MEDIUM 6.5 CVE-2024-34146 Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing a… Git Server after 114.v068a_c7cc2574 Fix from $1,6002024-05-02 HIGH 8.0 CVE-2024-2378 A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privileges on af-fected installatio… No fix yet Fix from $1,9502024-04-30 HIGH 8.1 CVE-2023-50363 An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al… Qts Mitigation only Fix from $1,9502024-04-26 CRITICAL 9.8 CVE-2023-51405 Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue a… Bookingpress 1.0.75+ Fix from $2,3002024-04-24 HIGH 7.5 CVE-2024-28627 An issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file. Mitigation only Fix from $1,9502024-04-23 MEDIUM 6.5 CVE-2024-32470 Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission check at all. This error was in… Tolgee 3.57.4+ Fix from $1,6002024-04-18 CRITICAL 9.8 CVE-2024-31452 OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization… Openfga 1.5.3+ Fix from $2,3002024-04-16 MEDIUM 5.3 CVE-2024-21120 Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affe… Outside In Technology Mitigation only Fix from $1,6002024-04-16 HIGH 7.2 CVE-2024-21083 Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Script Engine). Supported versions that are affected are 7.0.0.0.0 … Bi Publisher Mitigation only Fix from $1,9502024-04-16 CRITICAL 9.9 CVE-2024-21010 Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported… Hospitality Simphony after 19.5.4 Fix from $2,3002024-04-16 HIGH 7.5 CVE-2024-1738 An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations … Lunary 1.2.4+ Fix from $1,9502024-04-16 MEDIUM 6.3 CVE-2024-31990 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attac… Argo Cd 2.8.16 / 2.9.12+ Fix from $1,6002024-04-15 MEDIUM 6.5 CVE-2024-1307 The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a s… Smart Forms 2.6.94+ Fix from $1,6002024-04-15 HIGH 7.4 CVE-2024-27309 While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditi… Kafka after 3.6.1 Fix from $1,9502024-04-12 MEDIUM 5.0 CVE-2024-3388 A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and … Pan Os 8.1.26 / 9.0.17+ Fix from $1,6002024-04-10 CRITICAL 9.1 CVE-2024-1740 In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs b… Lunary 1.2.7+ Fix from $2,3002024-04-10 CRITICAL 9.1 CVE-2024-1741 lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates… Lunary 1.2.8+ Fix from $2,3002024-04-10 CRITICAL 9.1 CVE-2023-52538 Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect avai… Emui No fix yet Fix from $2,3002024-04-08