Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 6.5 CVE-2023-36611 The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” pri… Tbox Ms Cpu32 Firmware after 1.50.598 Fix from $1,6002023-07-03 CRITICAL 9.8 CVE-2023-34460 Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for… Tauri Patch available Fix from $2,3002023-06-23 MEDIUM 5.5 CVE-2023-0837 An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unpr… Remote 15.42.8+ Fix from $1,6002023-06-14 MEDIUM 6.5 CVE-2023-33142 Microsoft SharePoint Server Elevation of Privilege Vulnerability Sharepoint Server Patch available Fix from $1,6002023-06-14 HIGH 7.6 CVE-2023-32022 Windows Server Service Security Feature Bypass Vulnerability Windows Server 2012 Patch available Fix from $1,9502023-06-14 HIGH 8.1 CVE-2023-29152 By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account. Vuforia Studio 9.9+ Fix from $1,9502023-06-07 MEDIUM 5.4 CVE-2021-4344 The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking m… Frontend File Manager Plugin after 18.2 Fix from $1,6002023-06-07 HIGH 7.5 CVE-2020-36696 The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_d… Product Input Fields For Woocommerce 1.2.7+ Fix from $1,9502023-06-07 MEDIUM 6.5 CVE-2023-30948 A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorizatio… Foundry Comments 2.249.0+ Fix from $1,6002023-06-06 HIGH 7.5 CVE-2022-40521 Transient DOS due to improper authorization in Modem 315 5g Iot Modem Firmware No fix yet Fix from $1,9502023-06-06 HIGH 7.5 CVE-2022-40536 Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. 315 5g Iot Modem Firmware Mitigation only Fix from $1,9502023-06-06 HIGH 8.8 CVE-2023-32707EPSS 79% In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who hol… Splunk 8.1.14 / 8.2.11+ Fix from $1,9502023-06-01 MEDIUM 6.5 CVE-2023-34091 Kyverno is a policy engine designed for Kubernetes. In versions of Kyverno prior to 1.10.0, resources which have the `deletionTimestamp` field define… Kyverno 1.10.0+ Fix from $1,6002023-06-01 CRITICAL 9.8 CVE-2023-33189 Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. T… Pomerium 0.17.4 / 0.19.2+ Fix from $2,3002023-05-30 HIGH 8.1 CVE-2023-2950 Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1. Openemr 7.0.1+ Fix from $1,9502023-05-28 HIGH 7.5 CVE-2023-2496 The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper cap… Go Pricing after 3.3.19 Fix from $1,9502023-05-24 MEDIUM 5.5 CVE-2023-2782 Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build … Cyber Infrastructure 5.3.1-38+ Fix from $1,6002023-05-18 HIGH 7.5 CVE-2022-45450 Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Wi… Agent 15+ Fix from $1,9502023-05-18 HIGH 8.8 CVE-2023-20182 Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted … Catalyst Center 2.3.3.7 / 2.3.5.3+ Fix from $1,9502023-05-18 MEDIUM 6.5 CVE-2023-28325 An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMes… Rocket.chat 6.0.0+ Fix from $1,6002023-05-11 MEDIUM 5.5 CVE-2022-45128 Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service vi… Endpoint Management Assistant 1.9.0.0+ Fix from $1,6002023-05-10 MEDIUM 5.5 CVE-2022-43465 Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local ac… Setup And Configuration Software Mitigation only Fix from $1,6002023-05-10 MEDIUM 5.5 CVE-2022-41610 Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated… Endpoint Management Assistant Configuration Tool 1.0.4 / 2.4+ Fix from $1,6002023-05-10 MEDIUM 5.3 CVE-2023-28317 A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in a… Rocket.chat Mitigation only Fix from $1,6002023-05-09 MEDIUM 5.3 CVE-2023-28318 A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus s… Rocket.chat Mitigation only Fix from $1,6002023-05-09 MEDIUM 6.6 CVE-2023-29338 Visual Studio Code Spoofing Vulnerability Visual Studio Code 1.78.1+ Fix from $1,6002023-05-09 HIGH 8.1 CVE-2023-2534 Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and… Otrs 8.0.32+ Fix from $1,9502023-05-08 HIGH 8.6 CVE-2023-21505 Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox. Samsung Core Services 2.1.00.36+ Fix from $1,9502023-05-04 CRITICAL 9.8 CVE-2023-30467 This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to i… Ms N5008 Uc Firmware 71.9.0.18-r2 / 73.9.0.18-r2+ Fix from $2,3002023-04-28 CRITICAL 9.8 CVE-2023-2345 A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this issue is some unknown… Service Provider Management System Mitigation only Fix from $2,3002023-04-27