Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2023-46033
D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the…
Dsl 2730u Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-20261
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affe…
Catalyst Sd Wan Manager
Mitigation only
HIGH 8.3
CVE-2023-22102
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Di…
Mysql Connector\/j
after 8.1.0
CRITICAL 9.8
CVE-2023-43119
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain esca…
Exos
22.7 / 31.7.2+
HIGH 7.5
CVE-2023-5240
Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propaga…
Devolutions Server
after 2023.2.8.0
HIGH 7.8
CVE-2023-43079
Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged maliciou…
Emc Openmanage Server Administrator
11.0.1.0+
CRITICAL 9.8
CVE-2023-24479
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request …
Yf325 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-32632
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network r…
Yf325 Firmware
Mitigation only
CRITICAL 9.1
CVE-2023-44118
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiali…
Harmonyos
No fix yet
HIGH 7.8
CVE-2023-41772EPSS 12%
Win32k Elevation of Privilege Vulnerability
Windows 10 1809
10.0.17763.4974 / 10.0.19041.3570+
HIGH 7.8
CVE-2023-36725
Windows Kernel Elevation of Privilege Vulnerability
Windows 10 1809
10.0.17763.4974 / 10.0.19041.3570+
HIGH 7.3
CVE-2023-36561
Azure DevOps Server Elevation of Privilege Vulnerability
Azure Devops Server
Patch available
CRITICAL 9.6
CVE-2023-41679
An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.1…
Fortimanager
after 7.0.7
MEDIUM 6.7
CVE-2023-37194
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 162…
Simatic Cp 1604 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-5365
HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.
Life
1.8+
MEDIUM 6.5
CVE-2023-36820
Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, …
Micronaut Security
3.1.2 / 3.2.4+
CRITICAL 9.8
CVE-2023-43696
Improper Access Control in SICK APU allows an unprivileged remote attacker to
download as well as upload arbitrary files via anonymous access to the …
Apu0200 Firmware
4.0.0.6+
HIGH 7.1
CVE-2023-36465
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p…
Decidim
0.26.8 / 0.27.4+
HIGH 7.8
CVE-2023-43072
Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated a…
Smartfabric Storage Software
1.4.1+
HIGH 8.1
CVE-2023-1832
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of…
Satellite
4.3.7-3+
HIGH 7.8
CVE-2023-22618
If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privilege…
Wavelite Metro 200 And Fan Firmware
Mitigation only
HIGH 8.8
CVE-2023-0506
The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in t…
Airspace Cctv Web Service
Mitigation only
MEDIUM 6.5
CVE-2023-5353
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
Suitecrm
7.14.1+
HIGH 7.8
CVE-2023-24844
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.
Ar8035 Firmware
Mitigation only
HIGH 7.8
CVE-2023-21673
Improper Access to the VM resource manager can lead to Memory Corruption.
Aqt1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-5288
A remote unauthorized attacker may connect to the SIM1012, interact with the device and
change configuration settings. The adversary may also reset t…
Sim1012 0p0g200 Firmware
Mitigation only
HIGH 7.8
CVE-2023-32477
Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may …
Common Event Enabler
after 8.9.8.2
HIGH 8.2
CVE-2023-20223
A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an intern…
Dna Center
2.3.5.4+
HIGH 7.8
CVE-2023-32458
Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enab…
Appsync
after 4.6.0.0
MEDIUM 5.3
CVE-2023-41311
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.
Emui
No fix yet