Vulnerabilities (CVE)

Filtered by CWE-284
Total 7908 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42480 1 Clastix 1 Kamaji 2026-06-17 N/A 8.1 HIGH
Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This vulnerability is fixed in edge-24.8.2.
CVE-2024-42406 1 Mattermost 1 Mattermost Server 2026-06-17 N/A 5.4 MEDIUM
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.
CVE-2024-42354 1 Shopware 1 Shopware 2026-06-17 N/A 5.3 MEDIUM
Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition will be encoded to the final JSON. Prior to versions 6.6.5.1 and 6.5.8.13, the processing of the Criteria did not considered ManyToMany associations and so they were not considered properly and the protections didn't get used. This issue cannot be reproduced with the default entities by Shopware, but can be triggered with extensions. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older versions of 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin.
CVE-2024-42048 2026-06-17 N/A 6.5 MEDIUM
OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In combination with the application's behavior of loading DLLs from this location, this allows for DLL hijacking and may result in arbitrary code execution and privilege escalation.
CVE-2024-42033 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 6.9 MEDIUM
Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
CVE-2024-42023 1 Veeam 1 One 2026-06-17 N/A 8.8 HIGH
An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.
CVE-2024-42022 1 Veeam 1 One 2026-06-17 N/A 5.3 MEDIUM
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
CVE-2024-42021 1 Veeam 1 One 2026-06-17 N/A 6.5 MEDIUM
An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.
CVE-2024-41934 2026-06-17 N/A 5.9 MEDIUM
Improper access control in some Intel(R) GPA software before version 2024.3 may allow an authenticated user to potentially enable denial of service via local access.
CVE-2024-41926 1 Mattermost 1 Mattermost Server 2026-06-17 N/A 2.7 LOW
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.
CVE-2024-41912 1 Hp 1 Poly Clariti Manager 2026-06-17 N/A 9.8 CRITICAL
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.
CVE-2024-41905 1 Siemens 1 Sinec Traffic Analyzer 2026-06-17 N/A 6.8 MEDIUM
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get access to sensitive information.
CVE-2024-41806 2026-06-17 N/A 5.3 MEDIUM
The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These files are uploaded using the django default storage. With certain storage backends, uploads may become publicly available when the uploader uses versions master, palm, olive, nutmeg, maple, lilac, koa, or juniper. The patch in commit cb729a3ced0404736dfa0ae768526c82b608657b ensures that cohorts data uploaded to AWS S3 buckets is written with a private ACL. Beyond patching, deployers should also ensure that existing cohorts uploads have a private ACL, or that other precautions are taken to avoid public access.
CVE-2024-41732 1 Sap 1 Netweaver Application Server Abap 2026-06-17 N/A 4.7 MEDIUM
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application.
CVE-2024-41703 1 Librechat 1 Librechat 2026-06-17 N/A 9.8 CRITICAL
LibreChat through 0.7.4-rc1 has incorrect access control for message updates.
CVE-2024-41605 2026-06-17 N/A 8.4 HIGH
In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be executed.
CVE-2024-41600 1 Talelin 1 Lin-cms-spring-boot 2026-06-17 N/A 7.5 HIGH
Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.
CVE-2024-41518 1 Mecodia 1 Feripro 2026-06-17 N/A 7.5 HIGH
An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allows remote attackers to export an XLSX file with information about registrations and participants.
CVE-2024-41332 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 6.5 MEDIUM
Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.
CVE-2024-41309 1 Enjayworld 1 Enjay Crm 2026-06-17 N/A 7.8 HIGH
An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.