Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Display And Peripheral Manager HIGH 7.8
CVE-2024-22452

Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potentially …

Fix: 1.3+
Fix from $1,950 2024-03-04
Pair HIGH 7.1
CVE-2023-44281

Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system cou…

Fix: 1.2.1+
Fix from $1,950 2024-01-24
Harmonyos CRITICAL 9.1
CVE-2023-52106

Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affe…

Mitigation only
Fix from $2,300 2024-01-16
Ios Xr MEDIUM 5.3
CVE-2023-20190

A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker…

Fix: 7.3.5 / 7.5.4+
Fix from $1,600 2023-09-13
Emui HIGH 7.5
CVE-2023-39406

Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.

Mitigation only
Fix from $1,950 2023-08-13
Emui HIGH 7.5
CVE-2023-39391

Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,950 2023-08-13
Emui HIGH 7.5
CVE-2023-39394

Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modif…

Mitigation only
Fix from $1,950 2023-08-13
Emui MEDIUM 5.3
CVE-2023-39387

Vulnerability of permission control in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.

No fix yet
Fix from $1,600 2023-08-13
Emui HIGH 7.5
CVE-2023-39384

Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to p…

No fix yet
Fix from $1,950 2023-08-13
Emui HIGH 7.5
CVE-2023-39380

Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.

No fix yet
Fix from $1,950 2023-08-13
Best Fee Management System CRITICAL 9.8
CVE-2023-3599

A vulnerability was found in SourceCodester Best Fee Management System 1.0. It has been rated as critical. Affected by this issue is the function sav…

Mitigation only
Fix from $2,300 2023-07-10
Emui HIGH 7.5
CVE-2022-48508

Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.

No fix yet
Fix from $1,950 2023-07-06
Fastconnect 6900 Firmware HIGH 7.8
CVE-2023-21641

An app with non-privileged access can change global system brightness and cause undesired system behavior.

Patch available
Fix from $1,950 2023-07-04
Fortinac HIGH 7.5
CVE-2023-22633

An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.…

Fix: after 9.2.6
Fix from $1,950 2023-06-13
Shop Beat Media Player CRITICAL 9.8
CVE-2022-36246

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions.

Fix: 3.2.57+
Fix from $2,300 2023-05-30
Debian Linux MEDIUM 5.3
CVE-2023-2255

Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external…

Fix: 7.4.7 / 7.5.3+
Fix from $1,600 2023-05-25
Command \| Monitor HIGH 7.1
CVE-2023-24573

Dell Command | Monitor versions prior to 10.9 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicio…

Fix: 10.9+
Fix from $1,950 2023-02-10
Image Hover Effects Ultimate HIGH 7.2
CVE-2022-42459

Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.

Fix: after 9.7.1
Fix from $1,950 2022-11-18
Loginpress MEDIUM 5.3
CVE-2022-41839

Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking se…

Fix: after 1.6.2
Fix from $1,600 2022-11-18
Google Authenticator HIGH 8.8
CVE-2022-42461

Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.

Fix: 5.6.2+
Fix from $1,950 2022-11-18
Permalink Manager Lite CRITICAL 9.8
CVE-2022-41781

Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress.

Fix: 2.2.20.1+
Fix from $2,300 2022-11-18
Wooswipe Woocommerce Gallery HIGH 8.8
CVE-2022-45066

Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress.

Fix: after 2.0.1
Fix from $1,950 2022-11-17
Crowdsignal Dashboard HIGH 8.8
CVE-2022-45069

Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.

Fix: 3.0.10+
Fix from $1,950 2022-11-17
Ezoic MEDIUM 6.1
CVE-2022-41132

Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress.

Fix: after 2.8.8
Fix from $1,600 2022-11-17
Traffic Manager MEDIUM 5.4
CVE-2022-42460

Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress.

Fix: after 1.4.5
Fix from $1,600 2022-11-10
Zoho Crm Lead Magnet MEDIUM 6.5
CVE-2022-41978

Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.

Fix: after 1.7.5.8
Fix from $1,600 2022-11-09
Accordions HIGH 7.2
CVE-2022-38104

Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accord…

Fix: 2.1.0+
Fix from $1,950 2022-10-21
Drive HIGH 7.3
CVE-2022-3421

An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-…

Fix: 64.0+
Fix from $1,950 2022-10-17
Customer Reviews For Woocommerce HIGH 8.8
CVE-2022-38134

Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.

Fix: after 5.3.5
Fix from $1,950 2022-09-23
Awesome Filterable Portfolio MEDIUM 5.3
CVE-2022-35238

Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress.

Fix: after 1.9.7
Fix from $1,600 2022-09-23