Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Dsl 2730u Firmware MEDIUM 6.8
CVE-2023-46033

D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the…

Mitigation only
Fix from $1,600 2023-10-19
Catalyst Sd Wan Manager MEDIUM 6.5
CVE-2023-20261

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affe…

Mitigation only
Fix from $1,600 2023-10-18
Mysql Connector\/j HIGH 8.3
CVE-2023-22102

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Di…

Fix: after 8.1.0
Fix from $1,950 2023-10-17
Exos CRITICAL 9.8
CVE-2023-43119

An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain esca…

Fix: 22.7 / 31.7.2+
Fix from $2,300 2023-10-16
Devolutions Server HIGH 7.5
CVE-2023-5240

Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propaga…

Fix: after 2023.2.8.0
Fix from $1,950 2023-10-13
Emc Openmanage Server Administrator HIGH 7.8
CVE-2023-43079

Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged maliciou…

Fix: 11.0.1.0+
Fix from $1,950 2023-10-13
Yf325 Firmware CRITICAL 9.8
CVE-2023-24479

An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request …

Mitigation only
Fix from $2,300 2023-10-11
Yf325 Firmware CRITICAL 9.8
CVE-2023-32632

A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network r…

Mitigation only
Fix from $2,300 2023-10-11
Harmonyos CRITICAL 9.1
CVE-2023-44118

Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiali…

No fix yet
Fix from $2,300 2023-10-11
Windows 10 1809 HIGH 7.8
CVE-2023-41772EPSS 12%

Win32k Elevation of Privilege Vulnerability

Fix: 10.0.17763.4974 / 10.0.19041.3570+
Fix from $1,950 2023-10-10
Windows 10 1809 HIGH 7.8
CVE-2023-36725

Windows Kernel Elevation of Privilege Vulnerability

Fix: 10.0.17763.4974 / 10.0.19041.3570+
Fix from $1,950 2023-10-10
Azure Devops Server HIGH 7.3
CVE-2023-36561

Azure DevOps Server Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2023-10-10
Fortimanager CRITICAL 9.6
CVE-2023-41679

An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.1…

Fix: after 7.0.7
Fix from $2,300 2023-10-10
Simatic Cp 1604 Firmware MEDIUM 6.7
CVE-2023-37194

A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 162…

Mitigation only
Fix from $1,600 2023-10-10
Life CRITICAL 9.8
CVE-2023-5365

HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.

Fix: 1.8+
Fix from $2,300 2023-10-09
Micronaut Security MEDIUM 6.5
CVE-2023-36820

Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, …

Fix: 3.1.2 / 3.2.4+
Fix from $1,600 2023-10-09
Apu0200 Firmware CRITICAL 9.8
CVE-2023-43696

Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the …

Fix: 4.0.0.6+
Fix from $2,300 2023-10-09
Decidim HIGH 7.1
CVE-2023-36465

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p…

Fix: 0.26.8 / 0.27.4+
Fix from $1,950 2023-10-06
Smartfabric Storage Software HIGH 7.8
CVE-2023-43072

Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated a…

Fix: 1.4.1+
Fix from $1,950 2023-10-05
Satellite HIGH 8.1
CVE-2023-1832

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of…

Fix: 4.3.7-3+
Fix from $1,950 2023-10-04
Wavelite Metro 200 And Fan Firmware HIGH 7.8
CVE-2023-22618

If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privilege…

Mitigation only
Fix from $1,950 2023-10-04
Airspace Cctv Web Service HIGH 8.8
CVE-2023-0506

The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in t…

Mitigation only
Fix from $1,950 2023-10-03
Suitecrm MEDIUM 6.5
CVE-2023-5353

Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

Fix: 7.14.1+
Fix from $1,600 2023-10-03
Ar8035 Firmware HIGH 7.8
CVE-2023-24844

Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.

Mitigation only
Fix from $1,950 2023-10-03
Aqt1000 Firmware HIGH 7.8
CVE-2023-21673

Improper Access to the VM resource manager can lead to Memory Corruption.

Mitigation only
Fix from $1,950 2023-10-03
Sim1012 0p0g200 Firmware CRITICAL 9.8
CVE-2023-5288

A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset t…

Mitigation only
Fix from $2,300 2023-09-29
Common Event Enabler HIGH 7.8
CVE-2023-32477

Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may …

Fix: after 8.9.8.2
Fix from $1,950 2023-09-29
Dna Center HIGH 8.2
CVE-2023-20223

A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an intern…

Fix: 2.3.5.4+
Fix from $1,950 2023-09-27
Appsync HIGH 7.8
CVE-2023-32458

Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enab…

Fix: after 4.6.0.0
Fix from $1,950 2023-09-27
Emui MEDIUM 5.3
CVE-2023-41311

Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.

No fix yet
Fix from $1,600 2023-09-27