Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
M Files Server HIGH 7.8
CVE-2023-2112

Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.

Fix: 23.4.12455.0+
Fix from $1,950 2023-04-20
Powerjob MEDIUM 5.3
CVE-2023-29922

PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.

No fix yet
Fix from $1,600 2023-04-19
Teracopy MEDIUM 5.5
CVE-2023-29586

Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This leads to Arbitrary File Read …

No fix yet
Fix from $1,600 2023-04-19
Powerjob MEDIUM 5.3
CVE-2023-29921

PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create app interface.

No fix yet
Fix from $1,600 2023-04-19
MySQL HIGH 7.1
CVE-2023-21980

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior an…

Fix: after 8.0.32
Fix from $1,950 2023-04-18
Solaris HIGH 7.7
CVE-2023-21985

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily expl…

Mitigation only
Fix from $1,950 2023-04-18
Sql Developer MEDIUM 6.7
CVE-2023-21969

Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulner…

Fix: 23.1.0+
Fix from $1,600 2023-04-18
Health Sciences Inform MEDIUM 6.8
CVE-2023-21922

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are aff…

Fix: 6.3.1.3+
Fix from $1,600 2023-04-18
Health Sciences Inform HIGH 8.3
CVE-2023-21923

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are aff…

Fix: 6.3.1.3+
Fix from $1,950 2023-04-18
Banking Virtual Account Management MEDIUM 6.1
CVE-2023-21905

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). Supported…

Patch available
Fix from $1,600 2023-04-18
Nextcloud Files Automated Tagging HIGH 8.8
CVE-2023-30539

Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or bein…

Fix: 1.14.2 / 1.15.3+
Fix from $1,950 2023-04-17
Easyappointments MEDIUM 5.4
CVE-2023-2104

Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

Fix: 1.5.0+
Fix from $1,600 2023-04-15
Acrobat HIGH 7.8
CVE-2023-26408

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that…

Fix: after 23.001.20093
Fix from $1,950 2023-04-12
Acrobat HIGH 7.8
CVE-2023-26406

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that…

Fix: after 23.001.20093
Fix from $1,950 2023-04-12
Ds A71024 Firmware CRITICAL 9.8
CVE-2023-28808

Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacke…

Fix: after 2.3.8-8
Fix from $2,300 2023-04-11
Azure Machine Learning MEDIUM 6.5
CVE-2023-28312

Azure Machine Learning Information Disclosure Vulnerability

Fix: 3.0.02199.0001+
Fix from $1,600 2023-04-11
Azure Service Connector HIGH 7.5
CVE-2023-28300

Azure Service Connector Security Feature Bypass Vulnerability

Fix: 0.3.0+
Fix from $1,950 2023-04-11
Windows 11 21h2 HIGH 7.8
CVE-2023-28246

Windows Registry Elevation of Privilege Vulnerability

Fix: 10.0.22000.1817 / 10.0.22621.1555+
Fix from $1,950 2023-04-11
Bs Gsl2024 Firmware HIGH 8.1
CVE-2023-24544

Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific files of the product. As a res…

Fix: after 1.10-0.03
Fix from $1,950 2023-04-11
Power Manager HIGH 7.8
CVE-2023-28051

Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit t…

Fix: 3.11+
Fix from $1,950 2023-04-07
GitLab MEDIUM 5.3
CVE-2023-0319

An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all ve…

Fix: 15.8.5 / 15.9.4+
Fix from $1,600 2023-04-05
Phpmyfaq MEDIUM 5.4
CVE-2023-1883

Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

Fix: 3.1.12+
Fix from $1,600 2023-04-05
Richdocuments MEDIUM 6.5
CVE-2023-28645

Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich doc…

Fix: 6.3.2 / 7.0.2+
Fix from $1,600 2023-03-31
Nextcloud Server MEDIUM 6.5
CVE-2023-28844

Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still downloa…

Fix: 24.0.10 / 25.0.4+
Fix from $1,600 2023-03-31
Mediawiki MEDIUM 5.3
CVE-2023-29140

An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username …

Fix: after 1.39.3
Fix from $1,600 2023-03-31
Apps Graphql HIGH 7.5
CVE-2023-28877

The VTEX [email protected] GraphQL API module does not properly restrict unauthorized access to private configuration data. ([email protected] is unaff…

Mitigation only
Fix from $1,950 2023-03-31
Sql Monitor HIGH 8.8
CVE-2022-47542

Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.

Fix: 11.2.21 / 12.1.46+
Fix from $1,950 2023-03-30
Tl Wr940n Firmware MEDIUM 6.5
CVE-2022-24972

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 3.20.1 Build 20…

Mitigation only
Fix from $1,600 2023-03-28
Commerce MEDIUM 5.3
CVE-2023-22250

Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result …

Fix: 2.4.4+
Fix from $1,600 2023-03-27
Cal.com HIGH 8.8
CVE-2023-1647

Improper Access Control in GitHub repository calcom/cal.com prior to 2.7.

Fix: 2.7.0+
Fix from $1,950 2023-03-27