Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Emsigner MEDIUM 5.9
CVE-2023-43901

Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and priv…

No fix yet
Fix from $1,600 2023-11-14
Id.3 Firmware MEDIUM 6.3
CVE-2023-6073

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same ha…

Fix: 3.2+
Fix from $1,600 2023-11-10
Moodle MEDIUM 5.3
CVE-2023-5549

Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not hav…

Fix: 3.9.24 / 3.11.17+
Fix from $1,600 2023-11-09
Customer Reassurance Block MEDIUM 5.3
CVE-2023-47110

blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax funct…

Fix: 5.1.4+
Fix from $1,600 2023-11-09
Harmonyos HIGH 7.5
CVE-2023-46759

Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2023-11-08
Emui MEDIUM 5.3
CVE-2023-46755

Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to r…

No fix yet
Fix from $1,600 2023-11-08
Boltwire CRITICAL 9.1
CVE-2023-46501

An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password func…

No fix yet
Fix from $2,300 2023-11-07
Account MEDIUM 5.5
CVE-2023-42540

Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit int…

Fix: 14.5.01.1+
Fix from $1,600 2023-11-07
Discordsailv2 CRITICAL 9.8
CVE-2018-25093

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functional…

Fix: 2.10.3+
Fix from $2,300 2023-11-06
Discordsailv2 CRITICAL 9.8
CVE-2018-25092

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown f…

Fix: 2.10.3+
Fix from $2,300 2023-11-05
Virtual Gpu HIGH 7.1
CVE-2023-31019

NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrec…

Fix: 13.9 / 15.4+
Fix from $1,950 2023-11-02
Virtual Gpu HIGH 7.1
CVE-2023-31020

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access…

Fix: 13.9 / 15.4+
Fix from $1,950 2023-11-02
Freepbx HIGH 8.8
CVE-2023-43336

Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified param…

Fix: 15.0.16 / 15.0.18+
Fix from $1,950 2023-11-02
Secure Firewall Threat Defense MEDIUM 5.3
CVE-2023-20267

A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions.…

Fix: after 7.3.1.1
Fix from $1,600 2023-11-01
Anythingllm HIGH 8.8
CVE-2023-5833

Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.

Fix: 0.1.0+
Fix from $1,950 2023-10-30
Tvip 10000 Firmware HIGH 7.5
CVE-2018-17559

Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.

No fix yet
Fix from $1,950 2023-10-26
Polyeco500 Firmware CRITICAL 9.8
CVE-2023-46665

Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthor…

Mitigation only
Fix from $2,300 2023-10-26
Polyeco500 Firmware HIGH 8.1
CVE-2023-46663

Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface all…

Mitigation only
Fix from $1,950 2023-10-26
Polyeco500 Firmware CRITICAL 9.1
CVE-2023-46664

Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-sup…

Mitigation only
Fix from $2,300 2023-10-26
Polyeco500 Firmware CRITICAL 9.8
CVE-2023-46661

Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.

Mitigation only
Fix from $2,300 2023-10-26
Polyeco500 Firmware HIGH 7.5
CVE-2023-46662

Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote att…

Mitigation only
Fix from $1,950 2023-10-26
Analog Fm Transmitter Exc5000gx Firmware MEDIUM 6.5
CVE-2023-45228

The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissi…

Mitigation only
Fix from $1,600 2023-10-26
Elastic Sharepoint Online Python Connector MEDIUM 6.5
CVE-2023-46666

An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. …

Fix: 8.10.3.0+
Fix from $1,600 2023-10-26
Analog Fm Transmitter Exc5000gx Firmware CRITICAL 9.8
CVE-2023-42769

The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, b…

Mitigation only
Fix from $2,300 2023-10-26
Tiles MEDIUM 6.5
CVE-2023-30969

The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all…

Fix: 4.326.0+
Fix from $1,600 2023-10-26
Line HIGH 7.5
CVE-2023-38848

An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

No fix yet
Fix from $1,950 2023-10-25
Ctrlx Hmi Web Panel Wr2107 Firmware MEDIUM 6.8
CVE-2023-45844

The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application a…

Mitigation only
Fix from $1,600 2023-10-25
Sa Token CRITICAL 9.8
CVE-2023-44794

An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.

Fix: 1.37.0+
Fix from $2,300 2023-10-25
Unifi Network Application MEDIUM 5.3
CVE-2023-41721

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adop…

Fix: after 7.5.176
Fix from $1,600 2023-10-25
Kaibutsunosato MEDIUM 5.3
CVE-2023-39731

The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

Mitigation only
Fix from $1,600 2023-10-20