Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Glpi HIGH 8.8
CVE-2023-41322

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…

Fix: 10.0.10+
Fix from $1,950 2023-09-27
Siberiancms MEDIUM 6.5
CVE-2023-39376

SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network

Fix: 4.20.44 / 5.0.4+
Fix from $1,600 2023-09-27
A3700r Firmware CRITICAL 9.8
CVE-2023-43141

TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.

Mitigation only
Fix from $2,300 2023-09-25
Cumulus Linux HIGH 7.5
CVE-2023-25525

NVIDIA Cumulus Linux contains a vulnerability in forwarding where a VxLAN-encapsulated IPv6 packet received on an SVI interface with DMAC/DIPv6 set t…

Fix: 5.6.0+
Fix from $1,950 2023-09-20
Ekorrci Firmware CRITICAL 9.8
CVE-2022-47558

Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow a…

Mitigation only
Fix from $2,300 2023-09-19
Coldfusion HIGH 7.5
CVE-2023-38205 KEVEPSS 100%

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerabili…

Mitigation only
Fix from $1,950 2023-09-14
Coldfusion MEDIUM 5.3
CVE-2023-38206

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerabili…

Mitigation only
Fix from $1,600 2023-09-14
Ns Asg Firmware HIGH 7.5
CVE-2023-40850

netentsec NS-ASG 6.3 is vulnerable to Incorrect Access Control. There is a file leak in the website source code of the application security gateway.

No fix yet
Fix from $1,950 2023-09-13
Ios Xr HIGH 7.5
CVE-2023-20191

A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unaut…

Fix: 7.7.21 / 7.9.2+
Fix from $1,950 2023-09-13
Aptio V HIGH 7.8
CVE-2023-34470

AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the local network. A successful exploit of this …

Mitigation only
Fix from $1,950 2023-09-12
Qms Automotive HIGH 8.8
CVE-2023-40730

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient aut…

Fix: 12.39+
Fix from $1,950 2023-09-12
Sd Rom Utility HIGH 7.8
CVE-2023-3039

SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit t…

Fix: 1.0.2.0+
Fix from $1,950 2023-09-12
Tg852g Firmware CRITICAL 9.8
CVE-2023-40039

An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2…

Mitigation only
Fix from $2,300 2023-09-11
Crypto Currency Tracker CRITICAL 9.8
CVE-2023-37759

Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as a…

Fix: after 9.5
Fix from $2,300 2023-09-08
Serv U HIGH 7.2
CVE-2023-40060

A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authen…

Mitigation only
Fix from $1,950 2023-09-07
Coldfusion HIGH 7.4
CVE-2021-40699

ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when check…

Fix: 2018+
Fix from $1,950 2023-09-07
Magento HIGH 7.2
CVE-2021-36036

Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within …

Fix: 2.3.7 / 2.4.2+
Fix from $1,950 2023-09-06
Oas Platform CRITICAL 9.8
CVE-2023-31242

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-craft…

No fix yet
Fix from $2,300 2023-09-05
Memos CRITICAL 9.8
CVE-2023-4696

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

Fix: 0.13.2+
Fix from $2,300 2023-09-01
Yugabytedb HIGH 7.5
CVE-2023-4640

The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be s…

Fix: after 2.17.3.0
Fix from $1,950 2023-08-30
Jupyter Server MEDIUM 6.1
CVE-2023-40170

jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain f…

Fix: 2.7.2+
Fix from $1,600 2023-08-28
Smart S85f Management Platform MEDIUM 6.5
CVE-2023-4546

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic. Affected by this vulnerabilit…

Fix: after 2023-08-16
Fix from $1,600 2023-08-26
Openfga MEDIUM 6.5
CVE-2023-40579

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are v…

Fix: 1.3.1+
Fix from $1,600 2023-08-25
Xwiki HIGH 8.8
CVE-2023-40573

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain G…

Fix: 14.10.9+
Fix from $1,950 2023-08-24
Ideapad 1 14iau7 Firmware MEDIUM 6.7
CVE-2022-3746

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privil…

Mitigation only
Fix from $1,600 2023-08-23
Application Policy Infrastructure Controller MEDIUM 5.4
CVE-2023-20230

A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenti…

Fix: 5.2 / 6.0+
Fix from $1,600 2023-08-23
Lan W451ngr Firmware HIGH 8.8
CVE-2023-38132

LAN-W451NGR all versions provided by LOGITEC CORPORATION contains an improper access control vulnerability, which allows an unauthenticated attacker …

Mitigation only
Fix from $1,950 2023-08-18
Powerjob HIGH 7.5
CVE-2023-36106

An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for…

Fix: after 4.3.2
Fix from $1,950 2023-08-17
Lzma Software Development Kit MEDIUM 5.3
CVE-2023-39743

lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c.

No fix yet
Fix from $1,600 2023-08-17
Thousandeyes Enterprise Agent HIGH 7.8
CVE-2023-20224

A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker …

Fix: 0.230+
Fix from $1,950 2023-08-16