Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.5 CVE-2023-23508 The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. An app… macOS 11.7.3 / 12.6.3+ Fix from $1,6002023-02-27 MEDIUM 5.5 CVE-2022-32902 A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6, macOS Big Sur 11.7. An app … macOS 11.7 / 12.6+ Fix from $1,6002023-02-27 HIGH 7.5 CVE-2023-25821 Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improp… Nextcloud Server 24.0.7+ Fix from $1,9502023-02-25 HIGH 7.8 CVE-2023-1007 A vulnerability was found in Twister Antivirus 8.17. It has been declared as critical. This vulnerability affects the function 0x801120E4 in the libr… Twister Antivirus Patch available Fix from $1,9502023-02-24 MEDIUM 5.3 CVE-2023-0998 A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the f… Alphaware Simple E Commerce System No fix yet Fix from $1,6002023-02-24 CRITICAL 9.8 CVE-2023-0963 A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the … Music Gallery Site No fix yet Fix from $2,3002023-02-22 CRITICAL 9.8 CVE-2023-24320 An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors. Axcora No fix yet Fix from $2,3002023-02-21 CRITICAL 9.8 CVE-2023-22920 A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration… Lte3202 M437 Firmware Mitigation only Fix from $2,3002023-02-21 HIGH 8.8 CVE-2023-0916 A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown fu… Auto Dealer Management System No fix yet Fix from $1,9502023-02-19 MEDIUM 5.3 CVE-2023-22232EPSS 82% Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Sec… Connect after 12.1.5 Fix from $1,6002023-02-17 HIGH 8.2 CVE-2023-23923 The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that prefer… Moodle 3.9.19 / 3.11.12+ Fix from $1,9502023-02-17 HIGH 7.8 CVE-2023-24485 Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix… Workspace 2212+ Fix from $1,9502023-02-16 MEDIUM 5.5 CVE-2023-24484 A malicious user can cause log files to be written to a directory that they do not have permission to write to. Workspace 2212+ Fix from $1,6002023-02-16 MEDIUM 5.3 CVE-2023-23752 KEVEPSS 100% An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. Joomla\! 4.2.8+ Fix from $1,6002023-02-16 HIGH 8.8 CVE-2022-38935 An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/java/cn/niter/forum/controlle… Niterforum No fix yet Fix from $1,9502023-02-15 CRITICAL 9.8 CVE-2023-22807 LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker co… Xbc Dn32u Firmware Mitigation only Fix from $2,3002023-02-15 CRITICAL 9.8 CVE-2022-46892 In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex. Ampere Altra Firmware 2.10c+ Fix from $2,3002023-02-15 HIGH 7.8 CVE-2023-20927 In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local e… Android Mitigation only Fix from $1,9502023-02-15 HIGH 8.8 CVE-2023-21717 Microsoft SharePoint Server Elevation of Privilege Vulnerability Sharepoint Enterprise Server Patch available Fix from $1,9502023-02-14 HIGH 8.7 CVE-2023-21777 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability Azure App Service On Azure Stack Patch available Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-25149 TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, … Timescaledb after 2.9.2 Fix from $1,9502023-02-14 HIGH 7.5 CVE-2023-23835 A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions… Mendix 7.23.34 / 8.18.23+ Fix from $1,9502023-02-14 MEDIUM 5.3 CVE-2023-25161 Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server pri… Nextcloud Server 23.0.12 / 24.0.8+ Fix from $1,6002023-02-13 MEDIUM 5.3 CVE-2023-25159 Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app… Nextcloud Server 6.3.1+ Fix from $1,6002023-02-13 MEDIUM 6.5 CVE-2023-0661 Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data. Devolutions Server 2022.3.10.0+ Fix from $1,6002023-02-12 HIGH 7.8 CVE-2022-33243 Memory corruption due to improper access control in Qualcomm IPC. Apq8096au Firmware Patch available Fix from $1,9502023-02-12 MEDIUM 6.5 CVE-2022-46754 Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro l… Wyse Management Suite after 3.8.0 Fix from $1,6002023-02-11 MEDIUM 5.3 CVE-2023-24688 An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled. Mojoportal No fix yet Fix from $1,6002023-02-09 MEDIUM 5.5 CVE-2023-21442 Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows lo… Android Mitigation only Fix from $1,6002023-02-09 HIGH 7.8 CVE-2023-21445 Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android … Android Mitigation only Fix from $1,9502023-02-09