Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2024-24779 Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual dat… Superset 3.1.1+ Fix from $1,6002024-02-28 MEDIUM 5.4 CVE-2024-26016 A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby … Superset 3.0.4 / 3.1.1+ Fix from $1,6002024-02-28 MEDIUM 5.4 CVE-2023-3509 An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting fro… GitLab after 16.8.3 Fix from $1,6002024-02-21 HIGH 8.1 CVE-2023-46241 `discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an att… Microsoft Authentication 2024-02-20+ Fix from $1,9502024-02-21 MEDIUM 5.5 CVE-2023-42860 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1… macOS 12.7.1 / 13.6.1+ Fix from $1,6002024-02-21 HIGH 7.8 CVE-2024-1155 Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enab… Data Record Ad 2024_q1+ Fix from $1,9502024-02-20 HIGH 7.8 CVE-2024-1156 Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information an… Data Record Ad 2024_q1+ Fix from $1,9502024-02-20 MEDIUM 6.5 CVE-2024-25604 Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and … Digital Experience Platform 7.2 / 7.4.3.5+ Fix from $1,6002024-02-20 MEDIUM 5.4 CVE-2024-25149 Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsu… Digital Experience Platform 7.2 / 7.4.2+ Fix from $1,6002024-02-20 HIGH 7.5 CVE-2023-52374 Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affect service confidentiality. Emui No fix yet Fix from $1,9502024-02-18 HIGH 7.5 CVE-2023-52361 The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnerability may affect integrity. Harmonyos No fix yet Fix from $1,9502024-02-18 MEDIUM 5.4 CVE-2024-21987 SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter Server user to modify system … Snapcenter 5.0+ Fix from $1,6002024-02-16 MEDIUM 5.5 CVE-2024-0017 In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local informatio… Android Patch available Fix from $1,6002024-02-16 MEDIUM 6.5 CVE-2024-1482 An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public reposit… Enterprise Server 3.9.10 / 3.10.7+ Fix from $1,6002024-02-14 MEDIUM 5.5 CVE-2024-24966 When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.  Note: Software version… F5os A 1.6.0+ Fix from $1,6002024-02-14 MEDIUM 5.4 CVE-2023-6152 A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "veri… Grafana after 2.5.0 Fix from $1,6002024-02-13 HIGH 8.8 CVE-2024-24751 sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access… Event Management And Registration Patch available Fix from $1,9502024-02-13 HIGH 7.5 CVE-2024-23833 OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=… Openrefine 3.7.8+ Fix from $1,9502024-02-12 HIGH 8.8 CVE-2024-25108 Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attacke… Pixelfed 0.11.11+ Fix from $1,9502024-02-12 CRITICAL 9.8 CVE-2023-6036 The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functi… Web3 Crypto Wallet Login \& Nft Token Gating 3.0.0+ Fix from $2,3002024-02-12 HIGH 8.1 CVE-2023-51761 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire adm… Gc370xa Firmware Mitigation only Fix from $1,9502024-02-09 CRITICAL 9.1 CVE-2023-43609 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive informatio… Gc370xa Firmware Mitigation only Fix from $2,3002024-02-09 MEDIUM 6.5 CVE-2023-6564 An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define w… GitLab Mitigation only Fix from $1,6002024-02-08 HIGH 8.8 CVE-2024-24824EPSS 34% Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded… Graylog 5.1.11 / 5.2.4+ Fix from $1,9502024-02-07 MEDIUM 5.3 CVE-2023-6963 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible fo… Getwid 2.0.5+ Fix from $1,6002024-02-05 MEDIUM 6.5 CVE-2024-22208 phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any una… Phpmyfaq 3.2.5+ Fix from $1,6002024-02-05 MEDIUM 6.5 CVE-2023-32967 An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al… Qts Mitigation only Fix from $1,6002024-02-02 HIGH 8.8 CVE-2023-47142 IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate … Tivoli Application Dependency Discovery Manager after 7.3.0.10 Fix from $1,9502024-02-02 HIGH 8.8 CVE-2024-24573 facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user updates their profile, a POS… Facilemanager 4.5.1+ Fix from $1,9502024-01-31 CRITICAL 9.8 CVE-2024-23653 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running contain… Buildkit 0.12.5+ Fix from $2,3002024-01-31