Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.8 CVE-2024-22452 Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potentially … Display And Peripheral Manager 1.3+ Fix from $1,9502024-03-04 HIGH 7.1 CVE-2023-44281 Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system cou… Pair 1.2.1+ Fix from $1,9502024-01-24 CRITICAL 9.1 CVE-2023-52106 Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affe… Harmonyos Mitigation only Fix from $2,3002024-01-16 MEDIUM 5.3 CVE-2023-20190 A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker… Ios Xr 7.3.5 / 7.5.4+ Fix from $1,6002023-09-13 HIGH 7.5 CVE-2023-39406 Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart. Emui Mitigation only Fix from $1,9502023-08-13 HIGH 7.5 CVE-2023-39391 Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality. Emui No fix yet Fix from $1,9502023-08-13 HIGH 7.5 CVE-2023-39394 Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modif… Emui Mitigation only Fix from $1,9502023-08-13 MEDIUM 5.3 CVE-2023-39387 Vulnerability of permission control in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows. Emui No fix yet Fix from $1,6002023-08-13 HIGH 7.5 CVE-2023-39384 Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to p… Emui No fix yet Fix from $1,9502023-08-13 HIGH 7.5 CVE-2023-39380 Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally. Emui No fix yet Fix from $1,9502023-08-13 CRITICAL 9.8 CVE-2023-3599 A vulnerability was found in SourceCodester Best Fee Management System 1.0. It has been rated as critical. Affected by this issue is the function sav… Best Fee Management System Mitigation only Fix from $2,3002023-07-10 HIGH 7.5 CVE-2022-48508 Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity. Emui No fix yet Fix from $1,9502023-07-06 HIGH 7.8 CVE-2023-21641 An app with non-privileged access can change global system brightness and cause undesired system behavior. Fastconnect 6900 Firmware Patch available Fix from $1,9502023-07-04 HIGH 7.5 CVE-2023-22633 An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.… Fortinac after 9.2.6 Fix from $1,9502023-06-13 CRITICAL 9.8 CVE-2022-36246 Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions. Shop Beat Media Player 3.2.57+ Fix from $2,3002023-05-30 MEDIUM 5.3 CVE-2023-2255 Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external… Debian Linux 7.4.7 / 7.5.3+ Fix from $1,6002023-05-25 HIGH 7.1 CVE-2023-24573 Dell Command | Monitor versions prior to 10.9 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicio… Command \| Monitor 10.9+ Fix from $1,9502023-02-10 HIGH 7.2 CVE-2022-42459 Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress. Image Hover Effects Ultimate after 9.7.1 Fix from $1,9502022-11-18 MEDIUM 5.3 CVE-2022-41839 Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking se… Loginpress after 1.6.2 Fix from $1,6002022-11-18 HIGH 8.8 CVE-2022-42461 Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress. Google Authenticator 5.6.2+ Fix from $1,9502022-11-18 CRITICAL 9.8 CVE-2022-41781 Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress. Permalink Manager Lite 2.2.20.1+ Fix from $2,3002022-11-18 HIGH 8.8 CVE-2022-45066 Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress. Wooswipe Woocommerce Gallery after 2.0.1 Fix from $1,9502022-11-17 HIGH 8.8 CVE-2022-45069 Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress. Crowdsignal Dashboard 3.0.10+ Fix from $1,9502022-11-17 MEDIUM 6.1 CVE-2022-41132 Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress. Ezoic after 2.8.8 Fix from $1,6002022-11-17 MEDIUM 5.4 CVE-2022-42460 Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress. Traffic Manager after 1.4.5 Fix from $1,6002022-11-10 MEDIUM 6.5 CVE-2022-41978 Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress. Zoho Crm Lead Magnet after 1.7.5.8 Fix from $1,6002022-11-09 HIGH 7.2 CVE-2022-38104 Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accord… Accordions 2.1.0+ Fix from $1,9502022-10-21 HIGH 7.3 CVE-2022-3421 An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-… Drive 64.0+ Fix from $1,9502022-10-17 HIGH 8.8 CVE-2022-38134 Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. Customer Reviews For Woocommerce after 5.3.5 Fix from $1,9502022-09-23 MEDIUM 5.3 CVE-2022-35238 Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress. Awesome Filterable Portfolio after 1.9.7 Fix from $1,6002022-09-23