Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Commerce HIGH 7.5
CVE-2023-38220

Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Impro…

Mitigation only
Fix from $1,950 2023-10-13
Fortios HIGH 8.8
CVE-2023-41841

An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile t…

Fix: after 7.2.4
Fix from $1,950 2023-10-10
Helpdezk HIGH 8.6
CVE-2023-3037

Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to access the p…

Mitigation only
Fix from $1,950 2023-10-04
iOS CRITICAL 9.1
CVE-2023-20186

A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an aut…

Mitigation only
Fix from $2,300 2023-09-27
Android HIGH 7.8
CVE-2023-44123

The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary …

Mitigation only
Fix from $1,950 2023-09-27
Android HIGH 7.8
CVE-2023-44125

The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbit…

Mitigation only
Fix from $1,950 2023-09-27
Networker HIGH 8.8
CVE-2023-28055

Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network…

Fix: 19.7.0.5 / 19.8.0.3+
Fix from $1,950 2023-09-27
Apicast HIGH 7.5
CVE-2023-0456

A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul…

Fix: 2.12.2 / 2.13.2+
Fix from $1,950 2023-09-27
Ekorrci Firmware HIGH 7.5
CVE-2022-47553

Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive information for the organisati…

Mitigation only
Fix from $1,950 2023-09-19
Network Observability HIGH 7.5
CVE-2023-0813

A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic…

Mitigation only
Fix from $1,950 2023-09-15
Aqt1000 Firmware HIGH 7.5
CVE-2023-28584

Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA).

Patch available
Fix from $1,950 2023-09-05
9206 Lte Firmware HIGH 7.5
CVE-2023-33019

Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.

Patch available
Fix from $1,950 2023-09-05
9206 Lte Firmware HIGH 7.5
CVE-2023-33020

Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.

Patch available
Fix from $1,950 2023-09-05
Zulip Server MEDIUM 6.5
CVE-2023-32678

Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private…

Fix: 7.3+
Fix from $1,600 2023-08-25
Subscription Manager HIGH 7.8
CVE-2023-3899

A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red…

Fix: 1.28.39 / 1.29.37+
Fix from $1,950 2023-08-23
Emui CRITICAL 9.1
CVE-2023-39402

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri…

Mitigation only
Fix from $2,300 2023-08-13
Emui CRITICAL 9.1
CVE-2023-39403

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri…

Mitigation only
Fix from $2,300 2023-08-13
Emui CRITICAL 9.1
CVE-2023-39399

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri…

Mitigation only
Fix from $2,300 2023-08-13
Emui CRITICAL 9.1
CVE-2023-39400

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri…

Mitigation only
Fix from $2,300 2023-08-13
Emui CRITICAL 9.1
CVE-2023-39401

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri…

Mitigation only
Fix from $2,300 2023-08-13
Emui CRITICAL 9.1
CVE-2023-39398

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri…

Mitigation only
Fix from $2,300 2023-08-13
Next Unit Of Computing Firmware MEDIUM 6.7
CVE-2023-28385

Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable es…

Fix: 2.0.0.9+
Fix from $1,600 2023-08-11
Full Customer HIGH 8.8
CVE-2023-4243

The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, …

Fix: after 2.2.3
Fix from $1,950 2023-08-09
Sentry MEDIUM 6.5
CVE-2023-36826

Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can do…

Fix: 23.5.2+
Fix from $1,600 2023-07-25
Command Centre MEDIUM 5.4
CVE-2023-23568

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This iss…

Fix: 8.50.2831 / 8.60.2347+
Fix from $1,600 2023-07-25
Command Centre MEDIUM 5.4
CVE-2023-25074

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies. This issue …

Fix: 8.50.2831 / 8.60.2347+
Fix from $1,600 2023-07-25
Command Centre MEDIUM 6.5
CVE-2023-22428

Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre:…

Fix: 8.50.2831 / 8.60.2347+
Fix from $1,600 2023-07-24
Video Surveillance Management System CRITICAL 9.8
CVE-2023-3805

A vulnerability, which was classified as critical, has been found in Xiamen Four Letter Video Surveillance Management System up to 20230712. This iss…

Fix: after 2023-07-12
Fix from $2,300 2023-07-21
Customer Management Framework MEDIUM 6.5
CVE-2023-3574

Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1.

Fix: 3.4.1+
Fix from $1,600 2023-07-10
Gpu Display Driver HIGH 7.1
CVE-2023-25517

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which i…

Fix: 11.13 / 13.8+
Fix from $1,950 2023-07-04