Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Awslabs Sandbox Accounts For Events CRITICAL 9.0
CVE-2023-50928

"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Au…

Fix: 1.1.0+
Fix from $2,300 2023-12-22
Nextcloud Server MEDIUM 5.4
CVE-2023-49791

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well…

Fix: 23.0.12.13 / 24.0.12.9+
Fix from $1,600 2023-12-22
Wasmer HIGH 8.6
CVE-2023-51661

Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the browser. Wasm programs can acce…

Fix: 4.2.4+
Fix from $1,950 2023-12-22
Hertzbeat HIGH 7.5
CVE-2022-39337

Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v…

Fix: 1.2.1+
Fix from $1,950 2023-12-22
Online Notes Sharing System MEDIUM 5.4
CVE-2023-7055

A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /…

No fix yet
Fix from $1,600 2023-12-22
Airflow MEDIUM 6.5
CVE-2023-50783

Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to upda…

Fix: 2.8.0+
Fix from $1,600 2023-12-21
Hedron Domain Hook HIGH 7.8
CVE-2023-7025

A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This vulnerability affects the func…

Fix: after 3.8.0.12-0k0.5
Fix from $1,950 2023-12-21
Journalpump HIGH 7.5
CVE-2023-51390

journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump whic…

Fix: 2.5.0+
Fix from $1,950 2023-12-21
Etl3100 Firmware CRITICAL 9.8
CVE-2023-6930

EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability. This enables the attacker to …

Mitigation only
Fix from $2,300 2023-12-19
Debian Linux MEDIUM 5.5
CVE-2023-51384

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during ad…

Fix: 9.6+
Fix from $1,600 2023-12-18
Cpp14 Firmware MEDIUM 5.3
CVE-2022-41677

An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like …

Fix: after 8.80
Fix from $1,600 2023-12-18
Experience Manager MEDIUM 5.3
CVE-2023-48441

Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulner…

Fix: after 6.5.18.0
Fix from $1,600 2023-12-15
Azure Devops Server MEDIUM 6.5
CVE-2023-21751

Azure DevOps Server Spoofing Vulnerability

Patch available
Fix from $1,600 2023-12-14
Zed\! MEDIUM 5.5
CVE-2023-50440

ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualifica…

Fix: 2023.5+
Fix from $1,600 2023-12-13
Pos And Inventory Management System HIGH 8.8
CVE-2023-6773

A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is …

No fix yet
Fix from $1,950 2023-12-13
Icecms HIGH 8.8
CVE-2023-6761

A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the…

No fix yet
Fix from $1,950 2023-12-13
Silverpeas MEDIUM 5.4
CVE-2023-47325

Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to t…

Fix: 6.3.2+
Fix from $1,600 2023-12-13
Fortiproxy MEDIUM 5.3
CVE-2023-47536

An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy versio…

Fix: after 7.2.3
Fix from $1,600 2023-12-13
Rely Pcie Firmware HIGH 7.5
CVE-2023-47579

Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating …

Mitigation only
Fix from $1,950 2023-12-13
Mattermost Server MEDIUM 5.4
CVE-2023-6547

Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permiss…

Fix: after 9.2.1
Fix from $1,600 2023-12-12
Ar617vw Firmware HIGH 7.1
CVE-2022-48615

An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device inform…

No fix yet
Fix from $1,950 2023-12-12
Webmethods MEDIUM 6.5
CVE-2023-6578

A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.serve…

Fix: after 10.15.4
Fix from $1,600 2023-12-07
Qemu HIGH 7.1
CVE-2023-2861

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host s…

Fix: 8.1.0+
Fix from $1,950 2023-12-06
Qca6574 Firmware HIGH 7.8
CVE-2023-33071

Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.

Patch available
Fix from $1,950 2023-12-05
Rugged Control Center HIGH 7.8
CVE-2023-39257

Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentiall…

Fix: 4.7+
Fix from $1,950 2023-12-02
Rugged Control Center HIGH 7.8
CVE-2023-39256

Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentiall…

Fix: 4.7+
Fix from $1,950 2023-12-02
Prosafe Network Management System HIGH 7.8
CVE-2023-49694

A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in…

Fix: 1.7.0.31+
Fix from $1,950 2023-11-29
Client Relationship Management MEDIUM 5.0
CVE-2023-32063

OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call ev…

Fix: 5.0.4 / 5.1.1+
Fix from $1,600 2023-11-28
Orocommerce MEDIUM 5.8
CVE-2023-32065

OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be rece…

Fix: 5.0.11 / 5.1.1+
Fix from $1,600 2023-11-28
Command\|monitor HIGH 7.8
CVE-2023-44290

Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious standard user could potentially…

Fix: 10.10.0+
Fix from $1,950 2023-11-23