Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 8.8 CVE-2024-24830 OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability … Openobserve 0.8.0+ Fix from $1,9502024-02-08 MEDIUM 6.5 CVE-2024-25106 OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulne… Openobserve 0.8.0+ Fix from $1,6002024-02-08 MEDIUM 5.3 CVE-2024-23806 Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys. Omnikey Secure Elements Reader Configuration Cards Firmware Mitigation only Fix from $1,6002024-02-07 MEDIUM 5.3 CVE-2024-24936 In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed Teamcity 2023.11.2+ Fix from $1,6002024-02-06 MEDIUM 6.5 CVE-2023-32967 An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al… Qts Mitigation only Fix from $1,6002024-02-02 MEDIUM 6.5 CVE-2024-23649 Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, ev… Lemmy 0.19.1+ Fix from $1,6002024-01-24 HIGH 8.8 CVE-2023-40683 IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By au… Openpages With Watson 8.3.0.2.7+ Fix from $1,9502024-01-19 MEDIUM 5.4 CVE-2024-20979 Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0, 7.… Bi Publisher Patch available Fix from $1,6002024-01-16 MEDIUM 6.5 CVE-2023-6878 The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcss… Slick Social Share Buttons after 2.4.11 Fix from $1,6002024-01-11 MEDIUM 5.3 CVE-2023-6496 The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_… Manage Notification E Mails 1.8.6+ Fix from $1,6002024-01-11 MEDIUM 5.5 CVE-2023-40430 A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access removable volumes without user… macOS 14.0+ Fix from $1,6002024-01-10 HIGH 8.8 CVE-2023-48252 The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests. Nexo Os after 1500-sp2 Fix from $1,9502024-01-10 CRITICAL 9.6 CVE-2023-52139 Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that … Misskey 2023.12.1+ Fix from $2,3002023-12-29 MEDIUM 5.4 CVE-2023-41673 An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or back… Fortiadc after 7.0.5 Fix from $1,6002023-12-13 MEDIUM 6.5 CVE-2023-6538 SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Se… System Management Unit Firmware 14.8.7825.01+ Fix from $1,6002023-12-11 MEDIUM 6.5 CVE-2023-5808 SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage a… Vantara Hitachi Network Attached Storage after 14.8.7825.01 Fix from $1,6002023-12-05 MEDIUM 5.3 CVE-2023-48309 NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization a… Next Auth 4.24.5+ Fix from $1,6002023-11-20 HIGH 7.5 CVE-2023-48241EPSS 73% XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based se… Xwiki 14.10.5 / 15.5.1+ Fix from $1,9502023-11-20 MEDIUM 6.7 CVE-2023-32662 Improper authorization in some Intel Battery Life Diagnostic Tool installation software before version 2.2.1 may allow a privilaged user to potential… Battery Life Diagnostic Tool 2.2.1+ Fix from $1,6002023-11-14 HIGH 7.8 CVE-2023-28378 Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially … Quickassist Technology Library 1.10 / 2.04+ Fix from $1,9502023-11-14 MEDIUM 5.4 CVE-2023-36633 An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker … Fortimail 7.0.6 / 7.2.3+ Fix from $1,6002023-11-14 HIGH 8.1 CVE-2023-47109 PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When… Customer Reassurance Block 5.1.4+ Fix from $1,9502023-11-08 MEDIUM 5.3 CVE-2023-42541 Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id. Push Service 3.4.10+ Fix from $1,6002023-11-07 HIGH 7.8 CVE-2023-28556 Cryptographic issue in HLOS during key management. 315 5g Iot Modem Firmware No fix yet Fix from $1,9502023-11-07 MEDIUM 5.5 CVE-2023-5948 Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91. Amaze File Utilities 1.90+ Fix from $1,6002023-11-03 CRITICAL 9.8 CVE-2023-42491 EisBaer Scada - CWE-285: Improper Authorization Eisbaer Scada after 3.0.6433.1964 Fix from $2,3002023-10-25 HIGH 8.1 CVE-2020-36714 The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versio… Brizy after 1.0.125 Fix from $1,9502023-10-20 HIGH 8.8 CVE-2021-4334 The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the f… Fancy Product Designer 4.7.0+ Fix from $1,9502023-10-20 MEDIUM 6.3 CVE-2021-4335 The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing cap… Fancy Product Designer 4.7.0+ Fix from $1,6002023-10-20 MEDIUM 6.5 CVE-2023-5654 The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is acce… React Devtools 4.28.4+ Fix from $1,6002023-10-19