Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Proficy Historian MEDIUM 6.5
CVE-2022-43494

An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.

Fix: 2023+
Fix from $1,600 2023-01-18
Proficy Historian HIGH 8.1
CVE-2022-46331

An unauthorized user could possibly delete any file on the system.

Fix: 2023+
Fix from $1,950 2023-01-18
Hospitality Reporting And Analytics HIGH 8.1
CVE-2023-21828

Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The suppor…

Patch available
Fix from $1,950 2023-01-18
Ms 3000 Firmware CRITICAL 9.8
CVE-2022-43977

An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) l…

Fix: 3.7.6.25p0_3.2.2.17p0_4.7p0+
Fix from $2,300 2023-01-17
Little Software Stats CRITICAL 9.8
CVE-2015-10057

A vulnerability was found in Little Apps Little Software Stats. It has been declared as critical. Affected by this vulnerability is an unknown functi…

Fix: 0.2+
Fix from $2,300 2023-01-16
Inrouter302 Firmware HIGH 8.1
CVE-2023-22600

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CW…

Fix: 2.3.0.r5542 / 3.5.56+
Fix from $1,950 2023-01-12
Windows 10 1607 HIGH 7.1
CVE-2023-21750

Windows Kernel Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Windows 10 HIGH 7.1
CVE-2023-21752EPSS 5%

Windows Backup Service Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Sharepoint Foundation HIGH 8.8
CVE-2023-21742EPSS 56%

Microsoft SharePoint Server Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Azure Service Fabric HIGH 7.0
CVE-2023-21531

Azure Service Fabric Container Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Enterprise Home Screen HIGH 7.1
CVE-2022-36441

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to launch and use several other…

Mitigation only
Fix from $1,950 2023-01-10
Enterprise Home Screen MEDIUM 5.5
CVE-2022-36442

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is possible to install an unautho…

Mitigation only
Fix from $1,600 2023-01-10
Enterprise Home Screen HIGH 7.8
CVE-2022-36443

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communication channels (wireless and…

Mitigation only
Fix from $1,950 2023-01-10
Royal Elementor Addons HIGH 8.8
CVE-2022-4700

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in vers…

Fix: after 1.3.59
Fix from $1,950 2023-01-10
Royal Elementor Addons MEDIUM 6.5
CVE-2022-4702

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in vers…

Fix: after 1.3.59
Fix from $1,600 2023-01-10
Royal Elementor Addons HIGH 8.1
CVE-2022-4703

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versio…

Fix: after 1.3.59
Fix from $1,950 2023-01-10
Royal Elementor Addons HIGH 8.1
CVE-2022-4704

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in version…

Fix: after 1.3.59
Fix from $1,950 2023-01-10
Royal Elementor Addons MEDIUM 6.5
CVE-2022-4708

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in ver…

Fix: after 1.3.59
Fix from $1,600 2023-01-10
Royal Elementor Addons MEDIUM 6.5
CVE-2022-4709

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in vers…

Fix: after 1.3.59
Fix from $1,600 2023-01-10
Librephotos CRITICAL 9.8
CVE-2023-22903

api/views/user.py in LibrePhotos before e19e539 has incorrect access control.

Fix: 2023-01-09+
Fix from $2,300 2023-01-10
Netweaver Application Server For Java CRITICAL 9.8
CVE-2023-0017EPSS 16%

An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use…

Mitigation only
Fix from $2,300 2023-01-10
Host Agent MEDIUM 6.7
CVE-2023-0012

In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with…

Mitigation only
Fix from $1,600 2023-01-10
Weave Gitops HIGH 7.8
CVE-2022-23508

Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulne…

Fix: 0.12.0+
Fix from $1,950 2023-01-09
Investigate MEDIUM 5.3
CVE-2022-47543

An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects.

Fix: 12.1.7+
Fix from $1,600 2023-01-05
Halcyon CRITICAL 9.8
CVE-2021-4300

A vulnerability has been found in ghostlander Halcyon and classified as critical. Affected by this vulnerability is the function CBlock::AddToBlockIn…

Fix: 1.1.1.0+
Fix from $2,300 2023-01-04
M Link HIGH 8.1
CVE-2022-47634

M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via…

Mitigation only
Fix from $1,950 2023-01-01
Virtual Gpu HIGH 7.8
CVE-2022-34672

NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can compromise the security of t…

Fix: 11.11 / 13.6+
Fix from $1,950 2022-12-30
Memos HIGH 8.8
CVE-2022-4809

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,950 2022-12-28
Sc 6000 Wv02 Firmware CRITICAL 9.8
CVE-2022-45778

https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulner…

Fix: after 5.0.4.0
Fix from $2,300 2022-12-27
Dhi Dss7016d S2 Firmware HIGH 7.5
CVE-2022-45431

Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy…

Patch available
Fix from $1,950 2022-12-27