Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Openobserve HIGH 8.8
CVE-2024-24830

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability …

Fix: 0.8.0+
Fix from $1,950 2024-02-08
Openobserve MEDIUM 6.5
CVE-2024-25106

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulne…

Fix: 0.8.0+
Fix from $1,600 2024-02-08
Omnikey Secure Elements Reader Configuration Cards Firmware MEDIUM 5.3
CVE-2024-23806

Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.

Mitigation only
Fix from $1,600 2024-02-07
Teamcity MEDIUM 5.3
CVE-2024-24936

In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed

Fix: 2023.11.2+
Fix from $1,600 2024-02-06
Qts MEDIUM 6.5
CVE-2023-32967

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…

Mitigation only
Fix from $1,600 2024-02-02
Lemmy MEDIUM 6.5
CVE-2024-23649

Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, ev…

Fix: 0.19.1+
Fix from $1,600 2024-01-24
Openpages With Watson HIGH 8.8
CVE-2023-40683

IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By au…

Fix: 8.3.0.2.7+
Fix from $1,950 2024-01-19
Bi Publisher MEDIUM 5.4
CVE-2024-20979

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0, 7.…

Patch available
Fix from $1,600 2024-01-16
Slick Social Share Buttons MEDIUM 6.5
CVE-2023-6878

The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcss…

Fix: after 2.4.11
Fix from $1,600 2024-01-11
Manage Notification E Mails MEDIUM 5.3
CVE-2023-6496

The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_…

Fix: 1.8.6+
Fix from $1,600 2024-01-11
macOS MEDIUM 5.5
CVE-2023-40430

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access removable volumes without user…

Fix: 14.0+
Fix from $1,600 2024-01-10
Nexo Os HIGH 8.8
CVE-2023-48252

The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.

Fix: after 1500-sp2
Fix from $1,950 2024-01-10
Misskey CRITICAL 9.6
CVE-2023-52139

Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that …

Fix: 2023.12.1+
Fix from $2,300 2023-12-29
Fortiadc MEDIUM 5.4
CVE-2023-41673

An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or back…

Fix: after 7.0.5
Fix from $1,600 2023-12-13
System Management Unit Firmware MEDIUM 6.5
CVE-2023-6538

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Se…

Fix: 14.8.7825.01+
Fix from $1,600 2023-12-11
Vantara Hitachi Network Attached Storage MEDIUM 6.5
CVE-2023-5808

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage a…

Fix: after 14.8.7825.01
Fix from $1,600 2023-12-05
Next Auth MEDIUM 5.3
CVE-2023-48309

NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization a…

Fix: 4.24.5+
Fix from $1,600 2023-11-20
Xwiki HIGH 7.5
CVE-2023-48241EPSS 73%

XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based se…

Fix: 14.10.5 / 15.5.1+
Fix from $1,950 2023-11-20
Battery Life Diagnostic Tool MEDIUM 6.7
CVE-2023-32662

Improper authorization in some Intel Battery Life Diagnostic Tool installation software before version 2.2.1 may allow a privilaged user to potential…

Fix: 2.2.1+
Fix from $1,600 2023-11-14
Quickassist Technology Library HIGH 7.8
CVE-2023-28378

Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially …

Fix: 1.10 / 2.04+
Fix from $1,950 2023-11-14
Fortimail MEDIUM 5.4
CVE-2023-36633

An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker …

Fix: 7.0.6 / 7.2.3+
Fix from $1,600 2023-11-14
Customer Reassurance Block HIGH 8.1
CVE-2023-47109

PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When…

Fix: 5.1.4+
Fix from $1,950 2023-11-08
Push Service MEDIUM 5.3
CVE-2023-42541

Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.

Fix: 3.4.10+
Fix from $1,600 2023-11-07
315 5g Iot Modem Firmware HIGH 7.8
CVE-2023-28556

Cryptographic issue in HLOS during key management.

No fix yet
Fix from $1,950 2023-11-07
Amaze File Utilities MEDIUM 5.5
CVE-2023-5948

Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.

Fix: 1.90+
Fix from $1,600 2023-11-03
Eisbaer Scada CRITICAL 9.8
CVE-2023-42491

EisBaer Scada - CWE-285: Improper Authorization

Fix: after 3.0.6433.1964
Fix from $2,300 2023-10-25
Brizy HIGH 8.1
CVE-2020-36714

The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versio…

Fix: after 1.0.125
Fix from $1,950 2023-10-20
Fancy Product Designer HIGH 8.8
CVE-2021-4334

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the f…

Fix: 4.7.0+
Fix from $1,950 2023-10-20
Fancy Product Designer MEDIUM 6.3
CVE-2021-4335

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing cap…

Fix: 4.7.0+
Fix from $1,600 2023-10-20
React Devtools MEDIUM 6.5
CVE-2023-5654

The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is acce…

Fix: 4.28.4+
Fix from $1,600 2023-10-19