Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Retail Edge Program MEDIUM 5.5
CVE-2022-46279

Improper access control in the Intel(R) Retail Edge android application before version 3.0.301126-RELEASE may allow an authenticated user to potentia…

Fix: 3.0.301126+
Fix from $1,600 2023-05-10
One Boot Flash Update MEDIUM 6.7
CVE-2022-42465

Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privileged user to potentially enable …

Fix: 14.1.30+
Fix from $1,600 2023-05-10
One Boot Flash Update HIGH 7.8
CVE-2022-41784

Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially ena…

Fix: 14.1.30+
Fix from $1,950 2023-05-10
Connect M HIGH 7.8
CVE-2022-41769

Improper access control in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable escal…

Fix: 1.82+
Fix from $1,950 2023-05-10
Retail Edge Program HIGH 7.8
CVE-2022-41690

Improper access control in the Intel(R) Retail Edge Mobile iOS application before version 3.4.7 may allow an authenticated user to potentially enable…

Fix: 3.4.7+
Fix from $1,950 2023-05-10
Quickassist Technology MEDIUM 5.5
CVE-2022-41621

Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable informati…

Fix: 1.9.0+
Fix from $1,600 2023-05-10
Quickassist Technology HIGH 7.8
CVE-2022-40972

Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalatio…

Fix: 1.9.0+
Fix from $1,950 2023-05-10
System Usage Report HIGH 7.8
CVE-2022-40207

Improper access control in the Intel(R) SUR software before version 2.4.8989 may allow an authenticated user to potentially enable escalation of priv…

Fix: 2.4.8989+
Fix from $1,950 2023-05-10
Nuc Pro Software Suite HIGH 7.8
CVE-2022-32578

Improper access control for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalati…

Fix: 2.0.0.3+
Fix from $1,950 2023-05-10
Windows 10 20h2 HIGH 7.8
CVE-2023-24905

Remote Desktop Client Remote Code Execution Vulnerability

Fix: 10.0.19042.2965 / 10.0.19044.2965+
Fix from $1,950 2023-05-09
Dhis 2 MEDIUM 6.5
CVE-2023-31138

DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to version…

Fix: 2.37.9.1 / 2.38.3.1+
Fix from $1,600 2023-05-09
Dhis 2 MEDIUM 6.5
CVE-2023-32060

DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to version…

Fix: 2.36.13 / 2.37.8+
Fix from $1,600 2023-05-09
Android HIGH 7.8
CVE-2023-21491

Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system pri…

Mitigation only
Fix from $1,950 2023-05-04
Android MEDIUM 5.5
CVE-2023-21493

Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.

Mitigation only
Fix from $1,600 2023-05-04
Android MEDIUM 5.5
CVE-2023-21495

Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is …

Mitigation only
Fix from $1,600 2023-05-04
Android HIGH 7.8
CVE-2023-21488

Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.

Mitigation only
Fix from $1,950 2023-05-04
Android HIGH 7.1
CVE-2023-21490

Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.

Mitigation only
Fix from $1,950 2023-05-04
Alienware Command Center HIGH 7.8
CVE-2023-28070

Alienware Command Center Application, versions 5.5.43.0 and prior, contain an improper access control vulnerability. A local malicious user could pot…

Fix: 5.5.46.0+
Fix from $1,950 2023-05-03
Qam8295p Firmware HIGH 7.8
CVE-2023-21642

Memory corruption in HAB Memory management due to broad system privileges via physical address.

Mitigation only
Fix from $1,950 2023-05-02
Phpmyfaq CRITICAL 9.8
CVE-2023-2429

Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

Fix: 3.1.13+
Fix from $2,300 2023-04-30
Drivers Management HIGH 7.8
CVE-2023-25496

A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code wi…

Fix: 3.1.1307.1308+
Fix from $1,950 2023-04-28
Eos MEDIUM 6.5
CVE-2023-24512

On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to updat…

Fix: 4.26.10m / 4.27.9m+
Fix from $1,600 2023-04-25
Odoo HIGH 8.1
CVE-2021-45111

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the crea…

Fix: after 15.0
Fix from $1,950 2023-04-25
Odoo MEDIUM 6.5
CVE-2021-23176

Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remo…

Fix: after 15.0
Fix from $1,600 2023-04-25
Odoo HIGH 7.5
CVE-2021-23178

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a t…

Fix: after 15.0
Fix from $1,950 2023-04-25
Odoo HIGH 7.5
CVE-2021-23203

Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to do…

Patch available
Fix from $1,950 2023-04-25
Odoo MEDIUM 6.5
CVE-2021-44460

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the …

Fix: after 13.0
Fix from $1,600 2023-04-25
Powerjob CRITICAL 9.8
CVE-2023-29924

PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.

Mitigation only
Fix from $2,300 2023-04-21
Rosariosis MEDIUM 6.5
CVE-2023-2202

Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3.

Fix: 10.9.3+
Fix from $1,600 2023-04-21
Papercut Mf CRITICAL 9.8
CVE-2023-27350 KEVEPSS 100%

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is …

Fix: 20.1.7 / 21.2.11+
Fix from $2,300 2023-04-20