Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Modoboa CRITICAL 9.1
CVE-2023-2227EPSS 44%

Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.

Fix: 2.1.0+
Fix from $2,300 2023-04-21
Junos Os Evolved HIGH 7.1
CVE-2023-28973

An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker …

Fix: 20.4+
Fix from $1,950 2023-04-17
Access Management CRITICAL 9.8
CVE-2022-3748

Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5…

Fix: after 7.2.0
Fix from $2,300 2023-04-14
Synchronization Engine HIGH 7.8
CVE-2023-26466

A user with non-Admin access can change a configuration file on the client to modify the Server URL.

Fix: 3.1.30+
Fix from $1,950 2023-04-10
GitLab MEDIUM 5.3
CVE-2023-1167

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions sta…

Fix: 15.8.5 / 15.9.4+
Fix from $1,600 2023-04-05
Glpi HIGH 8.8
CVE-2023-28634

GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technic…

Fix: 9.5.13 / 10.0.7+
Fix from $1,950 2023-04-05
Vault MEDIUM 6.5
CVE-2023-0665

HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting …

Fix: 1.11.9 / 1.12.5+
Fix from $1,600 2023-03-30
Device Mapper Multipath HIGH 7.8
CVE-2022-3787

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in…

Mitigation only
Fix from $1,950 2023-03-29
Sdm600 HIGH 7.2
CVE-2022-3685

A vulnerability exists in the SDM600 software. The software operates at a privilege level that is higher than the minimum level required. An attacker…

Fix: 1.3+
Fix from $1,950 2023-03-28
Sdm600 CRITICAL 9.1
CVE-2022-3686

A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web servi…

Fix: 1.2.23000.291+
Fix from $2,300 2023-03-28
Sdm600 HIGH 7.5
CVE-2022-3683

A vulnerability exists in the SDM600 API web services authorization validation implementation. An attacker who successfully exploits the vulnerabili…

Fix: 1.2.23000.291+
Fix from $1,950 2023-03-28
Cilium HIGH 7.3
CVE-2023-27594

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, under speci…

Fix: 1.11.15 / 1.12.8+
Fix from $1,950 2023-03-17
Android MEDIUM 5.5
CVE-2023-21461

Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device …

Mitigation only
Fix from $1,600 2023-03-16
Wallabag MEDIUM 5.3
CVE-2023-0734

Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.

Fix: 2.5.4+
Fix from $1,600 2023-03-05
Finesse HIGH 7.5
CVE-2023-20088

A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated,…

Fix: 12.6+
Fix from $1,950 2023-03-03
Kylin Os HIGH 7.8
CVE-2023-1164

A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is some unknown functionality o…

Fix: 1.3.11-23 / 1.30.10-5.p23+
Fix from $1,950 2023-03-03
Pixelfed MEDIUM 5.3
CVE-2023-0914

Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4.

Fix: 0.11.4+
Fix from $1,600 2023-02-19
Diaenergie HIGH 8.8
CVE-2023-0822

The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass aut…

Fix: 1.9.03.001+
Fix from $1,950 2023-02-17
Fortinac CRITICAL 9.8
CVE-2022-38375

An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user t…

Fix: 7.2.0 / 9.2.7+
Fix from $2,300 2023-02-16
Powerpath Management Appliance HIGH 8.1
CVE-2022-34446

PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privil…

Mitigation only
Fix from $1,950 2023-02-11
Android MEDIUM 5.5
CVE-2023-21440

Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.

Mitigation only
Fix from $1,600 2023-02-09
Android MEDIUM 5.5
CVE-2023-21423

Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission…

Mitigation only
Fix from $1,600 2023-02-09
Smart Things HIGH 7.8
CVE-2023-21432

Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.

Fix: 1.7.93+
Fix from $1,950 2023-02-09
Galaxy Store HIGH 7.8
CVE-2023-21433

Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.

Fix: 4.5.49.8+
Fix from $1,950 2023-02-09
Android MEDIUM 5.5
CVE-2023-21422

Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server w…

Mitigation only
Fix from $1,600 2023-02-09
Command \| Intel Vpro Out Of Band HIGH 7.8
CVE-2023-23696

Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious user…

Fix: 4.4.0+
Fix from $1,950 2023-02-07
Unified Remote CRITICAL 9.8
CVE-2022-3229EPSS 66%

Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated a…

Fix: after 3.11.0.2483
Fix from $2,300 2023-02-06
Symfony HIGH 8.8
CVE-2022-24894

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse pr…

Fix: 4.4.50 / 5.4.2+
Fix from $1,950 2023-02-03
Ecostruxure Power Commission HIGH 7.8
CVE-2022-4062

A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets acces…

Fix: 2.26+
Fix from $1,950 2023-02-01
Realtek High Definition Audio Driver HIGH 7.3
CVE-2022-34405

An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit thi…

Fix: 6.0.9254.1 / 6.0.9388.1+
Fix from $1,950 2023-01-26