Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2023-29298 KEVEPSS 100% Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vu… Coldfusion Mitigation only Fix from $1,9502023-07-12 HIGH 7.8 CVE-2023-33155 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.4645 / 10.0.19041.3208+ Fix from $1,9502023-07-11 CRITICAL 10.0 CVE-2023-29130 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configurati… Simatic Cn 4100 Firmware 2.5+ Fix from $2,3002023-07-11 CRITICAL 9.8 CVE-2023-24489 KEVEPSS 94% A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated at… Sharefile Storage Zones Controller 5.11.24+ Fix from $2,3002023-07-10 MEDIUM 5.5 CVE-2023-24486 A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain acc… Workspace 2302+ Fix from $1,6002023-07-10 HIGH 7.5 CVE-2023-3271 Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data … Icr890 4 Firmware 2.5.0+ Fix from $1,9502023-07-10 HIGH 7.5 CVE-2023-3273 Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing sett… Icr890 4 Firmware 2.5.0+ Fix from $1,9502023-07-10 HIGH 8.1 CVE-2023-35939 GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a f… Glpi 10.0.8+ Fix from $1,9502023-07-05 HIGH 7.5 CVE-2023-35940 GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file a… Glpi 10.0.8+ Fix from $1,9502023-07-05 MEDIUM 6.5 CVE-2023-34107 GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights ch… Glpi 10.0.8+ Fix from $1,6002023-07-05 MEDIUM 6.5 CVE-2023-34106 GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights che… Glpi 10.0.8+ Fix from $1,6002023-07-05 HIGH 7.8 CVE-2023-21518 Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity. Searchwidget 3.3+ Fix from $1,9502023-06-28 MEDIUM 5.3 CVE-2023-3431 Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9. Fedora 1.2023.9+ Fix from $1,6002023-06-27 MEDIUM 6.5 CVE-2023-35173 Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid me… End To End Encryption 1.12.4+ Fix from $1,6002023-06-23 HIGH 8.1 CVE-2023-35927 NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server version… Nextcloud Server 19.0.13.9 / 20.0.14.14+ Fix from $1,9502023-06-23 MEDIUM 6.3 CVE-2023-35167 Remult is a CRUD framework for full-stack TypeScript. If you used the apiPrefilter option of the `@Entity` decorator, by setting it to a function tha… Remult 0.20.6+ Fix from $1,6002023-06-23 MEDIUM 5.4 CVE-2023-3304 Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9. Admidio 4.2.9+ Fix from $1,6002023-06-23 HIGH 7.3 CVE-2023-1862 Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient … Warp after 2023.3.381.0 Fix from $1,9502023-06-20 HIGH 7.5 CVE-2023-3305 A vulnerability was found in C-DATA Web Management System up to 20230607. It has been classified as critical. This affects an unknown part of the fil… Web Management System after 20230607 Fix from $1,9502023-06-18 CRITICAL 9.8 CVE-2023-3306EPSS 23% A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. It has been declared as critical. This vulnerability affects unknown code of the fil… Rg Ew1200g Firmware No fix yet Fix from $2,3002023-06-18 HIGH 7.5 CVE-2023-28809 Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfull… Ds K1t320efwx Firmware No fix yet Fix from $1,9502023-06-15 HIGH 8.8 CVE-2023-32009 Windows Collaborative Translation Framework Elevation of Privilege Vulnerability Windows 10 1607 10.0.14393.5989 / 10.0.17763.4499+ Fix from $1,9502023-06-14 HIGH 8.1 CVE-2023-24546 On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor … Cloudvision Portal after 2021.3 Fix from $1,9502023-06-13 HIGH 7.2 CVE-2022-39946 An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all v… Fortinac after 9.2.8 Fix from $1,9502023-06-13 MEDIUM 5.3 CVE-2023-2159 The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct … Cmp 4.1.8+ Fix from $1,6002023-06-09 CRITICAL 9.8 CVE-2021-4380 The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_pa… Pinterest Automatic Pin 4.14.4+ Fix from $2,3002023-06-07 HIGH 8.8 CVE-2021-4360 The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restri… Controlled Admin Access after 1.5.5 Fix from $1,9502023-06-07 HIGH 8.8 CVE-2021-4361 The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrat… Jobsearch Wp Job Board after 1.8.1 Fix from $1,9502023-06-07 MEDIUM 5.3 CVE-2021-4352 The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings funct… Jobsearch Wp Job Board after 1.8.1 Fix from $1,6002023-06-07 MEDIUM 6.5 CVE-2020-36721 The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is … Activello 1.0.6 / 1.1.2+ Fix from $1,6002023-06-07