Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.9 CVE-2023-43901 Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and priv… Emsigner No fix yet Fix from $1,6002023-11-14 MEDIUM 6.3 CVE-2023-6073 Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same ha… Id.3 Firmware 3.2+ Fix from $1,6002023-11-10 MEDIUM 5.3 CVE-2023-5549 Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not hav… Moodle 3.9.24 / 3.11.17+ Fix from $1,6002023-11-09 MEDIUM 5.3 CVE-2023-47110 blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax funct… Customer Reassurance Block 5.1.4+ Fix from $1,6002023-11-09 HIGH 7.5 CVE-2023-46759 Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos No fix yet Fix from $1,9502023-11-08 MEDIUM 5.3 CVE-2023-46755 Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to r… Emui No fix yet Fix from $1,6002023-11-08 CRITICAL 9.1 CVE-2023-46501 An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password func… Boltwire No fix yet Fix from $2,3002023-11-07 MEDIUM 5.5 CVE-2023-42540 Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit int… Account 14.5.01.1+ Fix from $1,6002023-11-07 CRITICAL 9.8 CVE-2018-25093 A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functional… Discordsailv2 2.10.3+ Fix from $2,3002023-11-06 CRITICAL 9.8 CVE-2018-25092 A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown f… Discordsailv2 2.10.3+ Fix from $2,3002023-11-05 HIGH 7.1 CVE-2023-31019 NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrec… Virtual Gpu 13.9 / 15.4+ Fix from $1,9502023-11-02 HIGH 7.1 CVE-2023-31020 NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access… Virtual Gpu 13.9 / 15.4+ Fix from $1,9502023-11-02 HIGH 8.8 CVE-2023-43336 Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified param… Freepbx 15.0.16 / 15.0.18+ Fix from $1,9502023-11-02 MEDIUM 5.3 CVE-2023-20267 A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions.… Secure Firewall Threat Defense after 7.3.1.1 Fix from $1,6002023-11-01 HIGH 8.8 CVE-2023-5833 Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0. Anythingllm 0.1.0+ Fix from $1,9502023-10-30 HIGH 7.5 CVE-2018-17559 Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras. Tvip 10000 Firmware No fix yet Fix from $1,9502023-10-26 CRITICAL 9.8 CVE-2023-46665 Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthor… Polyeco500 Firmware Mitigation only Fix from $2,3002023-10-26 HIGH 8.1 CVE-2023-46663 Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface all… Polyeco500 Firmware Mitigation only Fix from $1,9502023-10-26 CRITICAL 9.1 CVE-2023-46664 Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-sup… Polyeco500 Firmware Mitigation only Fix from $2,3002023-10-26 CRITICAL 9.8 CVE-2023-46661 Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests. Polyeco500 Firmware Mitigation only Fix from $2,3002023-10-26 HIGH 7.5 CVE-2023-46662 Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote att… Polyeco500 Firmware Mitigation only Fix from $1,9502023-10-26 MEDIUM 6.5 CVE-2023-45228 The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissi… Analog Fm Transmitter Exc5000gx Firmware Mitigation only Fix from $1,6002023-10-26 MEDIUM 6.5 CVE-2023-46666 An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. … Elastic Sharepoint Online Python Connector 8.10.3.0+ Fix from $1,6002023-10-26 CRITICAL 9.8 CVE-2023-42769 The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, b… Analog Fm Transmitter Exc5000gx Firmware Mitigation only Fix from $2,3002023-10-26 MEDIUM 6.5 CVE-2023-30969 The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all… Tiles 4.326.0+ Fix from $1,6002023-10-26 HIGH 7.5 CVE-2023-38848 An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. Line No fix yet Fix from $1,9502023-10-25 MEDIUM 6.8 CVE-2023-45844 The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application a… Ctrlx Hmi Web Panel Wr2107 Firmware Mitigation only Fix from $1,6002023-10-25 CRITICAL 9.8 CVE-2023-44794 An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL. Sa Token 1.37.0+ Fix from $2,3002023-10-25 MEDIUM 5.3 CVE-2023-41721 Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adop… Unifi Network Application after 7.5.176 Fix from $1,6002023-10-25 MEDIUM 5.3 CVE-2023-39731 The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. Kaibutsunosato Mitigation only Fix from $1,6002023-10-20