Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2022-43494 An unauthorized user could be able to read any file on the system, potentially exposing sensitive information. Proficy Historian 2023+ Fix from $1,6002023-01-18 HIGH 8.1 CVE-2022-46331 An unauthorized user could possibly delete any file on the system. Proficy Historian 2023+ Fix from $1,9502023-01-18 HIGH 8.1 CVE-2023-21828 Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The suppor… Hospitality Reporting And Analytics Patch available Fix from $1,9502023-01-18 CRITICAL 9.8 CVE-2022-43977 An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) l… Ms 3000 Firmware 3.7.6.25p0_3.2.2.17p0_4.7p0+ Fix from $2,3002023-01-17 CRITICAL 9.8 CVE-2015-10057 A vulnerability was found in Little Apps Little Software Stats. It has been declared as critical. Affected by this vulnerability is an unknown functi… Little Software Stats 0.2+ Fix from $2,3002023-01-16 HIGH 8.1 CVE-2023-22600 InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CW… Inrouter302 Firmware 2.3.0.r5542 / 3.5.56+ Fix from $1,9502023-01-12 HIGH 7.1 CVE-2023-21750 Windows Kernel Elevation of Privilege Vulnerability Windows 10 1607 No fix yet Fix from $1,9502023-01-10 HIGH 7.1 CVE-2023-21752EPSS 5% Windows Backup Service Elevation of Privilege Vulnerability Windows 10 No fix yet Fix from $1,9502023-01-10 HIGH 8.8 CVE-2023-21742EPSS 56% Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Foundation No fix yet Fix from $1,9502023-01-10 HIGH 7.0 CVE-2023-21531 Azure Service Fabric Container Elevation of Privilege Vulnerability Azure Service Fabric No fix yet Fix from $1,9502023-01-10 HIGH 7.1 CVE-2022-36441 An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to launch and use several other… Enterprise Home Screen Mitigation only Fix from $1,9502023-01-10 MEDIUM 5.5 CVE-2022-36442 An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is possible to install an unautho… Enterprise Home Screen Mitigation only Fix from $1,6002023-01-10 HIGH 7.8 CVE-2022-36443 An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communication channels (wireless and… Enterprise Home Screen Mitigation only Fix from $1,9502023-01-10 HIGH 8.8 CVE-2022-4700 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in vers… Royal Elementor Addons after 1.3.59 Fix from $1,9502023-01-10 MEDIUM 6.5 CVE-2022-4702 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in vers… Royal Elementor Addons after 1.3.59 Fix from $1,6002023-01-10 HIGH 8.1 CVE-2022-4703 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versio… Royal Elementor Addons after 1.3.59 Fix from $1,9502023-01-10 HIGH 8.1 CVE-2022-4704 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in version… Royal Elementor Addons after 1.3.59 Fix from $1,9502023-01-10 MEDIUM 6.5 CVE-2022-4708 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in ver… Royal Elementor Addons after 1.3.59 Fix from $1,6002023-01-10 MEDIUM 6.5 CVE-2022-4709 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in vers… Royal Elementor Addons after 1.3.59 Fix from $1,6002023-01-10 CRITICAL 9.8 CVE-2023-22903 api/views/user.py in LibrePhotos before e19e539 has incorrect access control. Librephotos 2023-01-09+ Fix from $2,3002023-01-10 CRITICAL 9.8 CVE-2023-0017EPSS 16% An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use… Netweaver Application Server For Java Mitigation only Fix from $2,3002023-01-10 MEDIUM 6.7 CVE-2023-0012 In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with… Host Agent Mitigation only Fix from $1,6002023-01-10 HIGH 7.8 CVE-2022-23508 Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulne… Weave Gitops 0.12.0+ Fix from $1,9502023-01-09 MEDIUM 5.3 CVE-2022-47543 An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects. Investigate 12.1.7+ Fix from $1,6002023-01-05 CRITICAL 9.8 CVE-2021-4300 A vulnerability has been found in ghostlander Halcyon and classified as critical. Affected by this vulnerability is the function CBlock::AddToBlockIn… Halcyon 1.1.1.0+ Fix from $2,3002023-01-04 HIGH 8.1 CVE-2022-47634 M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via… M Link Mitigation only Fix from $1,9502023-01-01 HIGH 7.8 CVE-2022-34672 NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can compromise the security of t… Virtual Gpu 11.11 / 13.6+ Fix from $1,9502022-12-30 HIGH 8.8 CVE-2022-4809 Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,9502022-12-28 CRITICAL 9.8 CVE-2022-45778 https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulner… Sc 6000 Wv02 Firmware after 5.0.4.0 Fix from $2,3002022-12-27 HIGH 7.5 CVE-2022-45431 Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy… Dhi Dss7016d S2 Firmware Patch available Fix from $1,9502022-12-27