Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Meeting Software Development Kit HIGH 7.8
CVE-2023-49647

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow a…

Fix: 5.14.14 / 5.15.12+
Fix from $1,950 2024-01-12
Cics Transaction Gateway HIGH 8.1
CVE-2023-47140

IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.

Mitigation only
Fix from $1,950 2024-01-08
Userpro HIGH 8.8
CVE-2023-6009

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the…

Fix: after 5.1.4
Fix from $1,950 2023-11-22
Fortify Scancentral Dast CRITICAL 9.8
CVE-2023-5913

Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited to gain elevated privileges.T…

Mitigation only
Fix from $2,300 2023-11-08
Vault HIGH 7.5
CVE-2023-5077

The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating …

Fix: 1.13.0+
Fix from $1,950 2023-09-29
Ban Users HIGH 8.8
CVE-2023-4153

The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to a missing capability check on…

Fix: after 1.5.3
Fix from $1,950 2023-09-13
Android HIGH 7.8
CVE-2023-21269

In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. Thi…

Patch available
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-30691

Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.

Mitigation only
Fix from $1,950 2023-08-10
Android HIGH 7.8
CVE-2023-30680

Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

Mitigation only
Fix from $1,950 2023-08-10
Consul HIGH 7.3
CVE-2023-3518

HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities.…

Mitigation only
Fix from $1,950 2023-08-09
Teamcity HIGH 8.8
CVE-2023-39173

In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access

Fix: 2023.05.2+
Fix from $1,950 2023-07-25
Nomad MEDIUM 5.3
CVE-2023-3300

HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users …

Fix: after 1.5.6
Fix from $1,600 2023-07-20
Terraform Enterprise HIGH 7.7
CVE-2023-3114

Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unautho…

Fix: 202306-1+
Fix from $1,950 2023-06-22
Spectrum Protect Backup Archive Client HIGH 7.8
CVE-2023-28956

IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access contro…

Fix: after 8.1.17.2
Fix from $1,950 2023-06-22
Consul MEDIUM 6.5
CVE-2023-2816

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote …

Fix: 1.15.3+
Fix from $1,600 2023-06-02
Minikube CRITICAL 9.8
CVE-2023-1174

This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube …

Mitigation only
Fix from $2,300 2023-05-24
Wp Data Access HIGH 8.8
CVE-2023-1874

The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of autho…

Fix: after 5.3.7
Fix from $1,950 2023-04-12
Android HIGH 7.8
CVE-2023-20957

In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confused deputy. This could lead to …

Patch available
Fix from $1,950 2023-03-24
Clearpass Policy Manager MEDIUM 6.5
CVE-2023-25591

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to …

Fix: after 6.10.8
Fix from $1,600 2023-03-22
Storage Plug In HIGH 8.8
CVE-2022-4041

Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escal…

Mitigation only
Fix from $1,950 2023-01-31
Storage Plug In HIGH 8.8
CVE-2022-4441

Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escal…

Mitigation only
Fix from $1,950 2023-01-31
Passwordstate MEDIUM 6.5
CVE-2022-4613

A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as critical. This issue affects so…

Fix: 9.5+
Fix from $1,600 2022-12-19
Passwordstate MEDIUM 6.5
CVE-2022-3876

A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This …

No fix yet
Fix from $1,600 2022-12-19
Facepay HIGH 8.8
CVE-2022-4281

A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /fac…

Mitigation only
Fix from $1,950 2022-12-05
Smart Campus System HIGH 7.5
CVE-2022-4280

A vulnerability, which was classified as problematic, has been found in Dot Tech Smart Campus System. Affected by this issue is some unknown function…

No fix yet
Fix from $1,950 2022-12-03
House Rental System CRITICAL 9.8
CVE-2022-4276

A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-…

No fix yet
Fix from $2,300 2022-12-03
Human Resource Management System CRITICAL 9.8
CVE-2022-4273

A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unk…

No fix yet
Fix from $2,300 2022-12-03
Warehouse Management System CRITICAL 9.8
CVE-2022-4272

A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /p…

No fix yet
Fix from $2,300 2022-12-03
Event Registration System CRITICAL 9.8
CVE-2022-4232

A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The ma…

Mitigation only
Fix from $2,300 2022-11-30
Erp HIGH 8.8
CVE-2022-3944

A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the fil…

No fix yet
Fix from $1,950 2022-11-11