Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Directus MEDIUM 5.5
CVE-2023-28443

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacte…

Fix: 9.23.3+
Fix from $1,600 2023-03-24
Coldfusion HIGH 8.6
CVE-2023-26360 KEVEPSS 97%

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that …

Patch available
Fix from $1,950 2023-03-23
Ios Xe HIGH 7.8
CVE-2023-20065

A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privi…

Mitigation only
Fix from $1,950 2023-03-23
E Commerce System CRITICAL 9.8
CVE-2023-1557

A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionalit…

Mitigation only
Fix from $2,300 2023-03-22
Clearpass Policy Manager MEDIUM 5.5
CVE-2023-25595

A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sens…

Fix: after 6.10.8
Fix from $1,600 2023-03-22
Galaxy HIGH 7.5
CVE-2023-27578

Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an…

Fix: 22.01+
Fix from $1,950 2023-03-20
Wise System Monitor HIGH 7.8
CVE-2023-1489

A vulnerability has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54 and classified as critical. Affected by this vulnerability is the …

No fix yet
Fix from $1,950 2023-03-18
Anti Virus Plus MEDIUM 5.5
CVE-2023-1490

A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1 and classified as critical. Affected by this issue is the function 0x220020 in the l…

No fix yet
Fix from $1,600 2023-03-18
Anti Virus Plus MEDIUM 5.5
CVE-2023-1491

A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been classified as critical. This affects the function 0x220020 in the libra…

No fix yet
Fix from $1,600 2023-03-18
Wise Force Deleter HIGH 7.1
CVE-2023-1486

A vulnerability classified as problematic was found in Lespeed WiseCleaner Wise Force Deleter 1.5.3.54. This vulnerability affects the function 0x220…

No fix yet
Fix from $1,950 2023-03-18
Anti Virus HIGH 7.1
CVE-2023-1453

A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. It has been rated as critical. Affected by this issue is the function 0x80002008 in the l…

No fix yet
Fix from $1,950 2023-03-17
Openssh CRITICAL 9.8
CVE-2023-28531

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is…

Fix: 9.3+
Fix from $2,300 2023-03-17
Android HIGH 8.1
CVE-2023-21457

Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permis…

Mitigation only
Fix from $1,950 2023-03-16
Bixbytouch MEDIUM 5.5
CVE-2023-21465

Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files.

Fix: 3.2.02.5+
Fix from $1,600 2023-03-16
Sysmac Cj2h Cpu64 Firmware CRITICAL 9.1
CVE-2023-0811

Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AR…

Mitigation only
Fix from $2,300 2023-03-16
Online Food Ordering System CRITICAL 9.8
CVE-2023-1432

A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this issue is some unknown functi…

Mitigation only
Fix from $2,300 2023-03-16
Aspera Faspex HIGH 7.5
CVE-2023-27875

IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847.

Patch available
Fix from $1,950 2023-03-16
Netiq Advanced Authentication CRITICAL 9.8
CVE-2023-24468

Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2

Fix: 6.3+
Fix from $2,300 2023-03-15
Netweaver Application Server For Java MEDIUM 5.3
CVE-2023-26460

Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities …

Mitigation only
Fix from $1,600 2023-03-14
Netweaver Application Server For Java MEDIUM 5.3
CVE-2023-27268

SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacke…

Mitigation only
Fix from $1,600 2023-03-14
Rocket.chat HIGH 7.5
CVE-2023-23911

An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changin…

Fix: 6.0.0+
Fix from $1,950 2023-03-10
Qam8295p Firmware HIGH 7.8
CVE-2022-40539

Memory corruption in Automotive Android OS due to improper validation of array index.

Mitigation only
Fix from $1,950 2023-03-10
GitLab HIGH 7.3
CVE-2022-4331

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all…

Fix: 15.7.8 / 15.8.4+
Fix from $1,950 2023-03-09
Feiqu Opensource HIGH 8.8
CVE-2023-27088

feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operation…

No fix yet
Fix from $1,950 2023-03-08
Fortisoar HIGH 7.2
CVE-2023-25605

A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perfo…

Fix: 7.3.2+
Fix from $1,950 2023-03-07
Rakuraku Pc Cloud Agent HIGH 7.5
CVE-2023-22335

Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to …

Fix: after 13.0.0.40
Fix from $1,950 2023-03-06
Xwiki HIGH 8.8
CVE-2023-26471

XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in re…

Fix: 13.10.10 / 14.4.6+
Fix from $1,950 2023-03-02
Xwiki MEDIUM 6.5
CVE-2023-26473

XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access da…

Fix: 13.10.11 / 14.4.7+
Fix from $1,600 2023-03-02
Xwiki HIGH 8.8
CVE-2023-26474

XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execut…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-03-02
Active Iq Unified Manager MEDIUM 6.5
CVE-2022-23240

Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows u…

Fix: 9.11p1+
Fix from $1,600 2023-02-28