Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.8 CVE-2023-2112 Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0. M Files Server 23.4.12455.0+ Fix from $1,9502023-04-20 MEDIUM 5.3 CVE-2023-29922 PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface. Powerjob No fix yet Fix from $1,6002023-04-19 MEDIUM 5.5 CVE-2023-29586 Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This leads to Arbitrary File Read … Teracopy No fix yet Fix from $1,6002023-04-19 MEDIUM 5.3 CVE-2023-29921 PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create app interface. Powerjob No fix yet Fix from $1,6002023-04-19 HIGH 7.1 CVE-2023-21980 Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior an… MySQL after 8.0.32 Fix from $1,9502023-04-18 HIGH 7.7 CVE-2023-21985 Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily expl… Solaris Mitigation only Fix from $1,9502023-04-18 MEDIUM 6.7 CVE-2023-21969 Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulner… Sql Developer 23.1.0+ Fix from $1,6002023-04-18 MEDIUM 6.8 CVE-2023-21922 Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are aff… Health Sciences Inform 6.3.1.3+ Fix from $1,6002023-04-18 HIGH 8.3 CVE-2023-21923 Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are aff… Health Sciences Inform 6.3.1.3+ Fix from $1,9502023-04-18 MEDIUM 6.1 CVE-2023-21905 Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). Supported… Banking Virtual Account Management Patch available Fix from $1,6002023-04-18 HIGH 8.8 CVE-2023-30539 Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or bein… Nextcloud Files Automated Tagging 1.14.2 / 1.15.3+ Fix from $1,9502023-04-17 MEDIUM 5.4 CVE-2023-2104 Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Easyappointments 1.5.0+ Fix from $1,6002023-04-15 HIGH 7.8 CVE-2023-26408 Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that… Acrobat after 23.001.20093 Fix from $1,9502023-04-12 HIGH 7.8 CVE-2023-26406 Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that… Acrobat after 23.001.20093 Fix from $1,9502023-04-12 CRITICAL 9.8 CVE-2023-28808 Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacke… Ds A71024 Firmware after 2.3.8-8 Fix from $2,3002023-04-11 MEDIUM 6.5 CVE-2023-28312 Azure Machine Learning Information Disclosure Vulnerability Azure Machine Learning 3.0.02199.0001+ Fix from $1,6002023-04-11 HIGH 7.5 CVE-2023-28300 Azure Service Connector Security Feature Bypass Vulnerability Azure Service Connector 0.3.0+ Fix from $1,9502023-04-11 HIGH 7.8 CVE-2023-28246 Windows Registry Elevation of Privilege Vulnerability Windows 11 21h2 10.0.22000.1817 / 10.0.22621.1555+ Fix from $1,9502023-04-11 HIGH 8.1 CVE-2023-24544 Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific files of the product. As a res… Bs Gsl2024 Firmware after 1.10-0.03 Fix from $1,9502023-04-11 HIGH 7.8 CVE-2023-28051 Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit t… Power Manager 3.11+ Fix from $1,9502023-04-07 MEDIUM 5.3 CVE-2023-0319 An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all ve… GitLab 15.8.5 / 15.9.4+ Fix from $1,6002023-04-05 MEDIUM 5.4 CVE-2023-1883 Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12. Phpmyfaq 3.1.12+ Fix from $1,6002023-04-05 MEDIUM 6.5 CVE-2023-28645 Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich doc… Richdocuments 6.3.2 / 7.0.2+ Fix from $1,6002023-03-31 MEDIUM 6.5 CVE-2023-28844 Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still downloa… Nextcloud Server 24.0.10 / 25.0.4+ Fix from $1,6002023-03-31 MEDIUM 5.3 CVE-2023-29140 An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username … Mediawiki after 1.39.3 Fix from $1,6002023-03-31 HIGH 7.5 CVE-2023-28877 The VTEX [email protected] GraphQL API module does not properly restrict unauthorized access to private configuration data. ([email protected] is unaff… Apps Graphql Mitigation only Fix from $1,9502023-03-31 HIGH 8.8 CVE-2022-47542 Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges. Sql Monitor 11.2.21 / 12.1.46+ Fix from $1,9502023-03-30 MEDIUM 6.5 CVE-2022-24972 This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 3.20.1 Build 20… Tl Wr940n Firmware Mitigation only Fix from $1,6002023-03-28 MEDIUM 5.3 CVE-2023-22250 Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result … Commerce 2.4.4+ Fix from $1,6002023-03-27 HIGH 8.8 CVE-2023-1647 Improper Access Control in GitHub repository calcom/cal.com prior to 2.7. Cal.com 2.7.0+ Fix from $1,9502023-03-27