Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.0 CVE-2023-50928 "Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Au… Awslabs Sandbox Accounts For Events 1.1.0+ Fix from $2,3002023-12-22 MEDIUM 5.4 CVE-2023-49791 Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well… Nextcloud Server 23.0.12.13 / 24.0.12.9+ Fix from $1,6002023-12-22 HIGH 8.6 CVE-2023-51661 Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the browser. Wasm programs can acce… Wasmer 4.2.4+ Fix from $1,9502023-12-22 HIGH 7.5 CVE-2022-39337 Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v… Hertzbeat 1.2.1+ Fix from $1,9502023-12-22 MEDIUM 5.4 CVE-2023-7055 A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /… Online Notes Sharing System No fix yet Fix from $1,6002023-12-22 MEDIUM 6.5 CVE-2023-50783 Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to upda… Airflow 2.8.0+ Fix from $1,6002023-12-21 HIGH 7.8 CVE-2023-7025 A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This vulnerability affects the func… Hedron Domain Hook after 3.8.0.12-0k0.5 Fix from $1,9502023-12-21 HIGH 7.5 CVE-2023-51390 journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump whic… Journalpump 2.5.0+ Fix from $1,9502023-12-21 CRITICAL 9.8 CVE-2023-6930 EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability. This enables the attacker to … Etl3100 Firmware Mitigation only Fix from $2,3002023-12-19 MEDIUM 5.5 CVE-2023-51384 In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during ad… Debian Linux 9.6+ Fix from $1,6002023-12-18 MEDIUM 5.3 CVE-2022-41677 An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like … Cpp14 Firmware after 8.80 Fix from $1,6002023-12-18 MEDIUM 5.3 CVE-2023-48441 Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulner… Experience Manager after 6.5.18.0 Fix from $1,6002023-12-15 MEDIUM 6.5 CVE-2023-21751 Azure DevOps Server Spoofing Vulnerability Azure Devops Server Patch available Fix from $1,6002023-12-14 MEDIUM 5.5 CVE-2023-50440 ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualifica… Zed\! 2023.5+ Fix from $1,6002023-12-13 HIGH 8.8 CVE-2023-6773 A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is … Pos And Inventory Management System No fix yet Fix from $1,9502023-12-13 HIGH 8.8 CVE-2023-6761 A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the… Icecms No fix yet Fix from $1,9502023-12-13 MEDIUM 5.4 CVE-2023-47325 Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to t… Silverpeas 6.3.2+ Fix from $1,6002023-12-13 MEDIUM 5.3 CVE-2023-47536 An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy versio… Fortiproxy after 7.2.3 Fix from $1,6002023-12-13 HIGH 7.5 CVE-2023-47579 Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating … Rely Pcie Firmware Mitigation only Fix from $1,9502023-12-13 MEDIUM 5.4 CVE-2023-6547 Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permiss… Mattermost Server after 9.2.1 Fix from $1,6002023-12-12 HIGH 7.1 CVE-2022-48615 An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device inform… Ar617vw Firmware No fix yet Fix from $1,9502023-12-12 MEDIUM 6.5 CVE-2023-6578 A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.serve… Webmethods after 10.15.4 Fix from $1,6002023-12-07 HIGH 7.1 CVE-2023-2861 A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host s… Qemu 8.1.0+ Fix from $1,9502023-12-06 HIGH 7.8 CVE-2023-33071 Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities. Qca6574 Firmware Patch available Fix from $1,9502023-12-05 HIGH 7.8 CVE-2023-39257 Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentiall… Rugged Control Center 4.7+ Fix from $1,9502023-12-02 HIGH 7.8 CVE-2023-39256 Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentiall… Rugged Control Center 4.7+ Fix from $1,9502023-12-02 HIGH 7.8 CVE-2023-49694 A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in… Prosafe Network Management System 1.7.0.31+ Fix from $1,9502023-11-29 MEDIUM 5.0 CVE-2023-32063 OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call ev… Client Relationship Management 5.0.4 / 5.1.1+ Fix from $1,6002023-11-28 MEDIUM 5.8 CVE-2023-32065 OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be rece… Orocommerce 5.0.11 / 5.1.1+ Fix from $1,6002023-11-28 HIGH 7.8 CVE-2023-44290 Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious standard user could potentially… Command\|monitor 10.10.0+ Fix from $1,9502023-11-23