Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2023-21427 Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition. Android Mitigation only Fix from $1,6002023-02-09 MEDIUM 5.3 CVE-2022-30564 Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the … Ipc Hf71242f Z X Firmware 2.800.0000000.4.r.210708 / 2.812.0000032.2.r.220804+ Fix from $1,6002023-02-09 HIGH 8.8 CVE-2022-47648 An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or au… B420 Firmware Mitigation only Fix from $1,9502023-02-08 MEDIUM 5.7 CVE-2023-25150 Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to … Richdocuments 3.8.7 / 4.2.9+ Fix from $1,6002023-02-08 CRITICAL 9.8 CVE-2023-0744EPSS 6% Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4. Answer 1.0.4+ Fix from $2,3002023-02-08 MEDIUM 5.3 CVE-2023-23615 Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear titl… Discourse after 3.0.0 Fix from $1,6002023-02-03 CRITICAL 9.8 CVE-2022-47699 COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control. Cf Wr623n Firmware Mitigation only Fix from $2,3002023-01-31 MEDIUM 6.5 CVE-2023-24425 Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup… Kubernetes Credentials Provider after 1.208.v128ee9800c04 Fix from $1,6002023-01-26 CRITICAL 9.8 CVE-2023-24022 Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily di… Rtd Firmware 3.7.11.6+ Fix from $2,3002023-01-26 HIGH 7.5 CVE-2023-0451 Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration … Eos Mitigation only Fix from $1,9502023-01-26 MEDIUM 6.5 CVE-2022-40036 An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /admi… Blog Ssm No fix yet Fix from $1,6002023-01-26 CRITICAL 9.8 CVE-2022-31704EPSS 81% The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive f… Vrealize Log Insight 8.10.2+ Fix from $2,3002023-01-26 HIGH 7.5 CVE-2023-22960EPSS 28% Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency. B2236 Firmware No fix yet Fix from $1,9502023-01-23 CRITICAL 9.8 CVE-2023-24028 In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function. Misp Patch available Fix from $2,3002023-01-20 HIGH 7.5 CVE-2020-22655 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10… R310 Firmware 3.6.2.0.795+ Fix from $1,9502023-01-20 HIGH 7.5 CVE-2023-22339 Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access r… Conprosys Hmi System after 3.4.5 Fix from $1,9502023-01-20 HIGH 7.8 CVE-2022-34457 Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path whi… Command\|configure 4.9.0+ Fix from $1,9502023-01-18 MEDIUM 6.3 CVE-2023-21860 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations). Supported versions that are affected are 7.4.3… Mysql Cluster after 8.0.31 Fix from $1,6002023-01-18 HIGH 7.5 CVE-2023-21893 Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Diffi… Database Server Patch available Fix from $1,9502023-01-18 HIGH 7.3 CVE-2023-21894 Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issue… Global Lifecycle Management Nextgen Oui Framework 13.9.4.2.11+ Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21849 Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported versions that are affected are 12… E Business Suite after 12.2.12 Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21850 Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: E-Business Collections). Supported versions that a… Demantra Demand Management Patch available Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21851 Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected… Marketing after 12.2.12 Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21852 Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Setup). Supported versions that are affected are 12.2… Learning Management after 12.2.12 Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21853 Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Synchronization). Supported versions that are affect… Mobile Field Service after 12.2.12 Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21854 Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Core Components). Supported versions that are affected are … Sales Offline after 12.2.12 Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21855 Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Pocket Outlook Sync(PocketPC)). Supported versions th… Sales For Handhelds after 12.2.12 Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21857 Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite). Supported versions that are… Hcm Common Architecture after 12.2.12 Fix from $1,9502023-01-18 HIGH 8.8 CVE-2023-21832 Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0… Bi Publisher Patch available Fix from $1,9502023-01-18 HIGH 8.8 CVE-2023-21846 Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0… Bi Publisher Patch available Fix from $1,9502023-01-18