Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.5 CVE-2023-28443 Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacte… Directus 9.23.3+ Fix from $1,6002023-03-24 HIGH 8.6 CVE-2023-26360 KEVEPSS 97% Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that … Coldfusion Patch available Fix from $1,9502023-03-23 HIGH 7.8 CVE-2023-20065 A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privi… Ios Xe Mitigation only Fix from $1,9502023-03-23 CRITICAL 9.8 CVE-2023-1557 A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionalit… E Commerce System Mitigation only Fix from $2,3002023-03-22 MEDIUM 5.5 CVE-2023-25595 A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sens… Clearpass Policy Manager after 6.10.8 Fix from $1,6002023-03-22 HIGH 7.5 CVE-2023-27578 Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an… Galaxy 22.01+ Fix from $1,9502023-03-20 HIGH 7.8 CVE-2023-1489 A vulnerability has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54 and classified as critical. Affected by this vulnerability is the … Wise System Monitor No fix yet Fix from $1,9502023-03-18 MEDIUM 5.5 CVE-2023-1490 A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1 and classified as critical. Affected by this issue is the function 0x220020 in the l… Anti Virus Plus No fix yet Fix from $1,6002023-03-18 MEDIUM 5.5 CVE-2023-1491 A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been classified as critical. This affects the function 0x220020 in the libra… Anti Virus Plus No fix yet Fix from $1,6002023-03-18 HIGH 7.1 CVE-2023-1486 A vulnerability classified as problematic was found in Lespeed WiseCleaner Wise Force Deleter 1.5.3.54. This vulnerability affects the function 0x220… Wise Force Deleter No fix yet Fix from $1,9502023-03-18 HIGH 7.1 CVE-2023-1453 A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. It has been rated as critical. Affected by this issue is the function 0x80002008 in the l… Anti Virus No fix yet Fix from $1,9502023-03-17 CRITICAL 9.8 CVE-2023-28531 ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is… Openssh 9.3+ Fix from $2,3002023-03-17 HIGH 8.1 CVE-2023-21457 Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permis… Android Mitigation only Fix from $1,9502023-03-16 MEDIUM 5.5 CVE-2023-21465 Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files. Bixbytouch 3.2.02.5+ Fix from $1,6002023-03-16 CRITICAL 9.1 CVE-2023-0811 Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AR… Sysmac Cj2h Cpu64 Firmware Mitigation only Fix from $2,3002023-03-16 CRITICAL 9.8 CVE-2023-1432 A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this issue is some unknown functi… Online Food Ordering System Mitigation only Fix from $2,3002023-03-16 HIGH 7.5 CVE-2023-27875 IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847. Aspera Faspex Patch available Fix from $1,9502023-03-16 CRITICAL 9.8 CVE-2023-24468 Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2 Netiq Advanced Authentication 6.3+ Fix from $2,3002023-03-15 MEDIUM 5.3 CVE-2023-26460 Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities … Netweaver Application Server For Java Mitigation only Fix from $1,6002023-03-14 MEDIUM 5.3 CVE-2023-27268 SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacke… Netweaver Application Server For Java Mitigation only Fix from $1,6002023-03-14 HIGH 7.5 CVE-2023-23911 An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changin… Rocket.chat 6.0.0+ Fix from $1,9502023-03-10 HIGH 7.8 CVE-2022-40539 Memory corruption in Automotive Android OS due to improper validation of array index. Qam8295p Firmware Mitigation only Fix from $1,9502023-03-10 HIGH 7.3 CVE-2022-4331 An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all… GitLab 15.7.8 / 15.8.4+ Fix from $1,9502023-03-09 HIGH 8.8 CVE-2023-27088 feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operation… Feiqu Opensource No fix yet Fix from $1,9502023-03-08 HIGH 7.2 CVE-2023-25605 A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perfo… Fortisoar 7.3.2+ Fix from $1,9502023-03-07 HIGH 7.5 CVE-2023-22335 Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to … Rakuraku Pc Cloud Agent after 13.0.0.40 Fix from $1,9502023-03-06 HIGH 8.8 CVE-2023-26471 XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in re… Xwiki 13.10.10 / 14.4.6+ Fix from $1,9502023-03-02 MEDIUM 6.5 CVE-2023-26473 XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access da… Xwiki 13.10.11 / 14.4.7+ Fix from $1,6002023-03-02 HIGH 8.8 CVE-2023-26474 XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execut… Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502023-03-02 MEDIUM 6.5 CVE-2022-23240 Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows u… Active Iq Unified Manager 9.11p1+ Fix from $1,6002023-02-28