Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
macOS MEDIUM 5.5
CVE-2023-23508

The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. An app…

Fix: 11.7.3 / 12.6.3+
Fix from $1,600 2023-02-27
macOS MEDIUM 5.5
CVE-2022-32902

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6, macOS Big Sur 11.7. An app …

Fix: 11.7 / 12.6+
Fix from $1,600 2023-02-27
Nextcloud Server HIGH 7.5
CVE-2023-25821

Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improp…

Fix: 24.0.7+
Fix from $1,950 2023-02-25
Twister Antivirus HIGH 7.8
CVE-2023-1007

A vulnerability was found in Twister Antivirus 8.17. It has been declared as critical. This vulnerability affects the function 0x801120E4 in the libr…

Patch available
Fix from $1,950 2023-02-24
Alphaware Simple E Commerce System MEDIUM 5.3
CVE-2023-0998

A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the f…

No fix yet
Fix from $1,600 2023-02-24
Music Gallery Site CRITICAL 9.8
CVE-2023-0963

A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the …

No fix yet
Fix from $2,300 2023-02-22
Axcora CRITICAL 9.8
CVE-2023-24320

An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.

No fix yet
Fix from $2,300 2023-02-21
Lte3202 M437 Firmware CRITICAL 9.8
CVE-2023-22920

A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration…

Mitigation only
Fix from $2,300 2023-02-21
Auto Dealer Management System HIGH 8.8
CVE-2023-0916

A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown fu…

No fix yet
Fix from $1,950 2023-02-19
Connect MEDIUM 5.3
CVE-2023-22232EPSS 82%

Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Sec…

Fix: after 12.1.5
Fix from $1,600 2023-02-17
Moodle HIGH 8.2
CVE-2023-23923

The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that prefer…

Fix: 3.9.19 / 3.11.12+
Fix from $1,950 2023-02-17
Workspace HIGH 7.8
CVE-2023-24485

Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix…

Fix: 2212+
Fix from $1,950 2023-02-16
Workspace MEDIUM 5.5
CVE-2023-24484

A malicious user can cause log files to be written to a directory that they do not have permission to write to.

Fix: 2212+
Fix from $1,600 2023-02-16
Joomla\! MEDIUM 5.3
CVE-2023-23752 KEVEPSS 100%

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

Fix: 4.2.8+
Fix from $1,600 2023-02-16
Niterforum HIGH 8.8
CVE-2022-38935

An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/java/cn/niter/forum/controlle…

No fix yet
Fix from $1,950 2023-02-15
Xbc Dn32u Firmware CRITICAL 9.8
CVE-2023-22807

LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker co…

Mitigation only
Fix from $2,300 2023-02-15
Ampere Altra Firmware CRITICAL 9.8
CVE-2022-46892

In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.

Fix: 2.10c+
Fix from $2,300 2023-02-15
Android HIGH 7.8
CVE-2023-20927

In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local e…

Mitigation only
Fix from $1,950 2023-02-15
Sharepoint Enterprise Server HIGH 8.8
CVE-2023-21717

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2023-02-14
Azure App Service On Azure Stack HIGH 8.7
CVE-2023-21777

Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2023-02-14
Timescaledb HIGH 8.8
CVE-2023-25149

TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, …

Fix: after 2.9.2
Fix from $1,950 2023-02-14
Mendix HIGH 7.5
CVE-2023-23835

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions…

Fix: 7.23.34 / 8.18.23+
Fix from $1,950 2023-02-14
Nextcloud Server MEDIUM 5.3
CVE-2023-25161

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server pri…

Fix: 23.0.12 / 24.0.8+
Fix from $1,600 2023-02-13
Nextcloud Server MEDIUM 5.3
CVE-2023-25159

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app…

Fix: 6.3.1+
Fix from $1,600 2023-02-13
Devolutions Server MEDIUM 6.5
CVE-2023-0661

Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.

Fix: 2022.3.10.0+
Fix from $1,600 2023-02-12
Apq8096au Firmware HIGH 7.8
CVE-2022-33243

Memory corruption due to improper access control in Qualcomm IPC.

Patch available
Fix from $1,950 2023-02-12
Wyse Management Suite MEDIUM 6.5
CVE-2022-46754

Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro l…

Fix: after 3.8.0
Fix from $1,600 2023-02-11
Mojoportal MEDIUM 5.3
CVE-2023-24688

An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled.

No fix yet
Fix from $1,600 2023-02-09
Android MEDIUM 5.5
CVE-2023-21442

Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows lo…

Mitigation only
Fix from $1,600 2023-02-09
Android HIGH 7.8
CVE-2023-21445

Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android …

Mitigation only
Fix from $1,950 2023-02-09