Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Command\|configure HIGH 7.8
CVE-2023-43086

Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local malicious user could potentially modif…

Fix: 4.11.0+
Fix from $1,950 2023-11-23
Command\|configure HIGH 7.8
CVE-2023-44289

Dell Command | Configure versions prior to 4.11.0, contain an improper access control vulnerability. A local malicious standard user could potentiall…

Fix: 4.11.0+
Fix from $1,950 2023-11-23
Os Recovery Tool HIGH 7.8
CVE-2023-39253

Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-admi…

Mitigation only
Fix from $1,950 2023-11-23
Tellus Lite V Simulator HIGH 8.8
CVE-2023-5299

A user with a standard account in Fuji Electric Tellus Lite may overwrite files in the system.

Fix: 4.0.19.0+
Fix from $1,950 2023-11-22
Nextcloud Server HIGH 7.1
CVE-2023-48239

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8…

Fix: 20.0.14.16 / 21.0.9.13+
Fix from $1,950 2023-11-21
Coldfusion HIGH 7.5
CVE-2023-26347EPSS 10%

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result i…

Fix: 2021+
Fix from $1,950 2023-11-17
Repository Manager HIGH 7.8
CVE-2023-44292

Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attack…

Fix: 3.4.4+
Fix from $1,950 2023-11-16
Repository Manager HIGH 7.8
CVE-2023-44282

Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attack…

Fix: after 3.4.3
Fix from $1,950 2023-11-16
Os Recovery Tool HIGH 7.8
CVE-2023-39259

Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-admi…

Mitigation only
Fix from $1,950 2023-11-16
Securecore Technology HIGH 7.1
CVE-2023-31100

Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification. This issue affects SecureCor…

Fix: 4.3.0.203 / 4.3.1.163+
Fix from $1,950 2023-11-15
Routeros MEDIUM 5.3
CVE-2023-41570

MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.

Fix: 7.12+
Fix from $1,600 2023-11-14
Smart Campus HIGH 7.8
CVE-2023-38411

Improper access control in the Intel Smart Campus android application before version 9.4 may allow an authenticated user to potentially enable escala…

Fix: 9.4+
Fix from $1,950 2023-11-14
Unison Software HIGH 8.8
CVE-2023-39221

Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network acce…

Fix: 20.14.2.3053 / 20.14.4244+
Fix from $1,950 2023-11-14
Unison Software HIGH 7.5
CVE-2023-39228

Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.

Fix: 20.14.2.3053 / 20.14.4244+
Fix from $1,950 2023-11-14
Support MEDIUM 5.5
CVE-2023-33872

Improper access control in the Intel Support android application all verions may allow an authenticated user to potentially enable information disclo…

Mitigation only
Fix from $1,600 2023-11-14
One Boot Flash Update HIGH 7.8
CVE-2023-32204

Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of priv…

Fix: 14.1.31+
Fix from $1,950 2023-11-14
Connectivity Performance Suite HIGH 7.5
CVE-2023-32279

Improper access control in user mode driver for some Intel(R) Connectivity Performance Suite before version 2.1123.214.2 may allow unauthenticated us…

Fix: 2.1123.214.2+
Fix from $1,950 2023-11-14
One Boot Flash Update HIGH 7.8
CVE-2023-29157

Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of priv…

Fix: 14.1.31+
Fix from $1,950 2023-11-14
Aptio V Uefi Firmware Integrator Tools HIGH 7.8
CVE-2023-28397

Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privi…

Mitigation only
Fix from $1,950 2023-11-14
Unison Software HIGH 7.2
CVE-2023-22448

Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of privilege via network access.

Fix: 20.14.2.3053 / 20.14.4244+
Fix from $1,950 2023-11-14
Unison Software HIGH 7.5
CVE-2023-22285

Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.

Fix: 20.14.2.3053 / 20.14.4244+
Fix from $1,950 2023-11-14
In Band Manageability HIGH 7.8
CVE-2022-41689

Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated user to potentially enable esca…

Fix: 3.0.14+
Fix from $1,950 2023-11-14
Aptio V Uefi Firmware Integrator Tools MEDIUM 6.7
CVE-2022-36374

Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user…

Mitigation only
Fix from $1,600 2023-11-14
Aptio V Uefi Firmware Integrator Tools MEDIUM 6.7
CVE-2022-36396

Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged us…

Mitigation only
Fix from $1,600 2023-11-14
Battery Life Diagnostic Tool HIGH 7.8
CVE-2022-38786

Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enabl…

Fix: 2.2.1+
Fix from $1,950 2023-11-14
Fortiedr MEDIUM 5.5
CVE-2023-44248

An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow …

Fix: after 5.2.0.4549
Fix from $1,600 2023-11-14
Windows 10 1607 MEDIUM 5.5
CVE-2023-36404

Windows Kernel Information Disclosure Vulnerability

Fix: 10.0.14393.6452 / 10.0.17763.5122+
Fix from $1,600 2023-11-14
Fortiadc HIGH 8.8
CVE-2023-26205

An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all ve…

Fix: after 7.0.5
Fix from $1,950 2023-11-14
Comos HIGH 7.5
CVE-2023-46601

A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection…

Mitigation only
Fix from $1,950 2023-11-14
Comos MEDIUM 6.5
CVE-2023-43505

A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an…

Mitigation only
Fix from $1,600 2023-11-14