Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Android MEDIUM 6.5
CVE-2023-21427

Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition.

Mitigation only
Fix from $1,600 2023-02-09
Ipc Hf71242f Z X Firmware MEDIUM 5.3
CVE-2022-30564

Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the …

Fix: 2.800.0000000.4.r.210708 / 2.812.0000032.2.r.220804+
Fix from $1,600 2023-02-09
B420 Firmware HIGH 8.8
CVE-2022-47648

An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or au…

Mitigation only
Fix from $1,950 2023-02-08
Richdocuments MEDIUM 5.7
CVE-2023-25150

Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to …

Fix: 3.8.7 / 4.2.9+
Fix from $1,600 2023-02-08
Answer CRITICAL 9.8
CVE-2023-0744EPSS 6%

Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.

Fix: 1.0.4+
Fix from $2,300 2023-02-08
Discourse MEDIUM 5.3
CVE-2023-23615

Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear titl…

Fix: after 3.0.0
Fix from $1,600 2023-02-03
Cf Wr623n Firmware CRITICAL 9.8
CVE-2022-47699

COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control.

Mitigation only
Fix from $2,300 2023-01-31
Kubernetes Credentials Provider MEDIUM 6.5
CVE-2023-24425

Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup…

Fix: after 1.208.v128ee9800c04
Fix from $1,600 2023-01-26
Rtd Firmware CRITICAL 9.8
CVE-2023-24022

Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily di…

Fix: 3.7.11.6+
Fix from $2,300 2023-01-26
Eos HIGH 7.5
CVE-2023-0451

Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration …

Mitigation only
Fix from $1,950 2023-01-26
Blog Ssm MEDIUM 6.5
CVE-2022-40036

An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /admi…

No fix yet
Fix from $1,600 2023-01-26
Vrealize Log Insight CRITICAL 9.8
CVE-2022-31704EPSS 81%

The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive f…

Fix: 8.10.2+
Fix from $2,300 2023-01-26
B2236 Firmware HIGH 7.5
CVE-2023-22960EPSS 28%

Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.

No fix yet
Fix from $1,950 2023-01-23
Misp CRITICAL 9.8
CVE-2023-24028

In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.

Patch available
Fix from $2,300 2023-01-20
R310 Firmware HIGH 7.5
CVE-2020-22655

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10…

Fix: 3.6.2.0.795+
Fix from $1,950 2023-01-20
Conprosys Hmi System HIGH 7.5
CVE-2023-22339

Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access r…

Fix: after 3.4.5
Fix from $1,950 2023-01-20
Command\|configure HIGH 7.8
CVE-2022-34457

Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path whi…

Fix: 4.9.0+
Fix from $1,950 2023-01-18
Mysql Cluster MEDIUM 6.3
CVE-2023-21860

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations). Supported versions that are affected are 7.4.3…

Fix: after 8.0.31
Fix from $1,600 2023-01-18
Database Server HIGH 7.5
CVE-2023-21893

Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Diffi…

Patch available
Fix from $1,950 2023-01-18
Global Lifecycle Management Nextgen Oui Framework HIGH 7.3
CVE-2023-21894

Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issue…

Fix: 13.9.4.2.11+
Fix from $1,950 2023-01-18
E Business Suite HIGH 7.5
CVE-2023-21849

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported versions that are affected are 12…

Fix: after 12.2.12
Fix from $1,950 2023-01-18
Demantra Demand Management HIGH 7.5
CVE-2023-21850

Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: E-Business Collections). Supported versions that a…

Patch available
Fix from $1,950 2023-01-18
Marketing HIGH 7.5
CVE-2023-21851

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected…

Fix: after 12.2.12
Fix from $1,950 2023-01-18
Learning Management HIGH 7.5
CVE-2023-21852

Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Setup). Supported versions that are affected are 12.2…

Fix: after 12.2.12
Fix from $1,950 2023-01-18
Mobile Field Service HIGH 7.5
CVE-2023-21853

Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Synchronization). Supported versions that are affect…

Fix: after 12.2.12
Fix from $1,950 2023-01-18
Sales Offline HIGH 7.5
CVE-2023-21854

Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Core Components). Supported versions that are affected are …

Fix: after 12.2.12
Fix from $1,950 2023-01-18
Sales For Handhelds HIGH 7.5
CVE-2023-21855

Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Pocket Outlook Sync(PocketPC)). Supported versions th…

Fix: after 12.2.12
Fix from $1,950 2023-01-18
Hcm Common Architecture HIGH 7.5
CVE-2023-21857

Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite). Supported versions that are…

Fix: after 12.2.12
Fix from $1,950 2023-01-18
Bi Publisher HIGH 8.8
CVE-2023-21832

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0…

Patch available
Fix from $1,950 2023-01-18
Bi Publisher HIGH 8.8
CVE-2023-21846

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0…

Patch available
Fix from $1,950 2023-01-18