Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Coldfusion HIGH 7.5
CVE-2023-29298 KEVEPSS 100%

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vu…

Mitigation only
Fix from $1,950 2023-07-12
Windows 10 1809 HIGH 7.8
CVE-2023-33155

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Fix: 10.0.17763.4645 / 10.0.19041.3208+
Fix from $1,950 2023-07-11
Simatic Cn 4100 Firmware CRITICAL 10.0
CVE-2023-29130

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configurati…

Fix: 2.5+
Fix from $2,300 2023-07-11
Sharefile Storage Zones Controller CRITICAL 9.8
CVE-2023-24489 KEVEPSS 94%

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated at…

Fix: 5.11.24+
Fix from $2,300 2023-07-10
Workspace MEDIUM 5.5
CVE-2023-24486

A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain acc…

Fix: 2302+
Fix from $1,600 2023-07-10
Icr890 4 Firmware HIGH 7.5
CVE-2023-3271

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data …

Fix: 2.5.0+
Fix from $1,950 2023-07-10
Icr890 4 Firmware HIGH 7.5
CVE-2023-3273

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing sett…

Fix: 2.5.0+
Fix from $1,950 2023-07-10
Glpi HIGH 8.1
CVE-2023-35939

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a f…

Fix: 10.0.8+
Fix from $1,950 2023-07-05
Glpi HIGH 7.5
CVE-2023-35940

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file a…

Fix: 10.0.8+
Fix from $1,950 2023-07-05
Glpi MEDIUM 6.5
CVE-2023-34107

GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights ch…

Fix: 10.0.8+
Fix from $1,600 2023-07-05
Glpi MEDIUM 6.5
CVE-2023-34106

GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights che…

Fix: 10.0.8+
Fix from $1,600 2023-07-05
Searchwidget HIGH 7.8
CVE-2023-21518

Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.

Fix: 3.3+
Fix from $1,950 2023-06-28
Fedora MEDIUM 5.3
CVE-2023-3431

Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.

Fix: 1.2023.9+
Fix from $1,600 2023-06-27
End To End Encryption MEDIUM 6.5
CVE-2023-35173

Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid me…

Fix: 1.12.4+
Fix from $1,600 2023-06-23
Nextcloud Server HIGH 8.1
CVE-2023-35927

NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server version…

Fix: 19.0.13.9 / 20.0.14.14+
Fix from $1,950 2023-06-23
Remult MEDIUM 6.3
CVE-2023-35167

Remult is a CRUD framework for full-stack TypeScript. If you used the apiPrefilter option of the `@Entity` decorator, by setting it to a function tha…

Fix: 0.20.6+
Fix from $1,600 2023-06-23
Admidio MEDIUM 5.4
CVE-2023-3304

Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

Fix: 4.2.9+
Fix from $1,600 2023-06-23
Warp HIGH 7.3
CVE-2023-1862

Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient …

Fix: after 2023.3.381.0
Fix from $1,950 2023-06-20
Web Management System HIGH 7.5
CVE-2023-3305

A vulnerability was found in C-DATA Web Management System up to 20230607. It has been classified as critical. This affects an unknown part of the fil…

Fix: after 20230607
Fix from $1,950 2023-06-18
Rg Ew1200g Firmware CRITICAL 9.8
CVE-2023-3306EPSS 23%

A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. It has been declared as critical. This vulnerability affects unknown code of the fil…

No fix yet
Fix from $2,300 2023-06-18
Ds K1t320efwx Firmware HIGH 7.5
CVE-2023-28809

Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfull…

No fix yet
Fix from $1,950 2023-06-15
Windows 10 1607 HIGH 8.8
CVE-2023-32009

Windows Collaborative Translation Framework Elevation of Privilege Vulnerability

Fix: 10.0.14393.5989 / 10.0.17763.4499+
Fix from $1,950 2023-06-14
Cloudvision Portal HIGH 8.1
CVE-2023-24546

On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor …

Fix: after 2021.3
Fix from $1,950 2023-06-13
Fortinac HIGH 7.2
CVE-2022-39946

An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all v…

Fix: after 9.2.8
Fix from $1,950 2023-06-13
Cmp MEDIUM 5.3
CVE-2023-2159

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct …

Fix: 4.1.8+
Fix from $1,600 2023-06-09
Pinterest Automatic Pin CRITICAL 9.8
CVE-2021-4380

The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_pa…

Fix: 4.14.4+
Fix from $2,300 2023-06-07
Controlled Admin Access HIGH 8.8
CVE-2021-4360

The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restri…

Fix: after 1.5.5
Fix from $1,950 2023-06-07
Jobsearch Wp Job Board HIGH 8.8
CVE-2021-4361

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrat…

Fix: after 1.8.1
Fix from $1,950 2023-06-07
Jobsearch Wp Job Board MEDIUM 5.3
CVE-2021-4352

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings funct…

Fix: after 1.8.1
Fix from $1,600 2023-06-07
Activello MEDIUM 6.5
CVE-2020-36721

The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is …

Fix: 1.0.6 / 1.1.2+
Fix from $1,600 2023-06-07