Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
CRITICAL 9.1 CVE-2023-2227EPSS 44% Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0. Modoboa 2.1.0+ Fix from $2,3002023-04-21 HIGH 7.1 CVE-2023-28973 An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker … Junos Os Evolved 20.4+ Fix from $1,9502023-04-17 CRITICAL 9.8 CVE-2022-3748 Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5… Access Management after 7.2.0 Fix from $2,3002023-04-14 HIGH 7.8 CVE-2023-26466 A user with non-Admin access can change a configuration file on the client to modify the Server URL. Synchronization Engine 3.1.30+ Fix from $1,9502023-04-10 MEDIUM 5.3 CVE-2023-1167 Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions sta… GitLab 15.8.5 / 15.9.4+ Fix from $1,6002023-04-05 HIGH 8.8 CVE-2023-28634 GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technic… Glpi 9.5.13 / 10.0.7+ Fix from $1,9502023-04-05 MEDIUM 6.5 CVE-2023-0665 HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting … Vault 1.11.9 / 1.12.5+ Fix from $1,6002023-03-30 HIGH 7.8 CVE-2022-3787 A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in… Device Mapper Multipath Mitigation only Fix from $1,9502023-03-29 HIGH 7.2 CVE-2022-3685 A vulnerability exists in the SDM600 software. The software operates at a privilege level that is higher than the minimum level required. An attacker… Sdm600 1.3+ Fix from $1,9502023-03-28 CRITICAL 9.1 CVE-2022-3686 A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web servi… Sdm600 1.2.23000.291+ Fix from $2,3002023-03-28 HIGH 7.5 CVE-2022-3683 A vulnerability exists in the SDM600 API web services authorization validation implementation. An attacker who successfully exploits the vulnerabili… Sdm600 1.2.23000.291+ Fix from $1,9502023-03-28 HIGH 7.3 CVE-2023-27594 Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, under speci… Cilium 1.11.15 / 1.12.8+ Fix from $1,9502023-03-17 MEDIUM 5.5 CVE-2023-21461 Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device … Android Mitigation only Fix from $1,6002023-03-16 MEDIUM 5.3 CVE-2023-0734 Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4. Wallabag 2.5.4+ Fix from $1,6002023-03-05 HIGH 7.5 CVE-2023-20088 A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated,… Finesse 12.6+ Fix from $1,9502023-03-03 HIGH 7.8 CVE-2023-1164 A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is some unknown functionality o… Kylin Os 1.3.11-23 / 1.30.10-5.p23+ Fix from $1,9502023-03-03 MEDIUM 5.3 CVE-2023-0914 Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4. Pixelfed 0.11.4+ Fix from $1,6002023-02-19 HIGH 8.8 CVE-2023-0822 The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass aut… Diaenergie 1.9.03.001+ Fix from $1,9502023-02-17 CRITICAL 9.8 CVE-2022-38375 An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user t… Fortinac 7.2.0 / 9.2.7+ Fix from $2,3002023-02-16 HIGH 8.1 CVE-2022-34446 PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privil… Powerpath Management Appliance Mitigation only Fix from $1,9502023-02-11 MEDIUM 5.5 CVE-2023-21440 Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture. Android Mitigation only Fix from $1,6002023-02-09 MEDIUM 5.5 CVE-2023-21423 Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission… Android Mitigation only Fix from $1,6002023-02-09 HIGH 7.8 CVE-2023-21432 Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner. Smart Things 1.7.93+ Fix from $1,9502023-02-09 HIGH 7.8 CVE-2023-21433 Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store. Galaxy Store 4.5.49.8+ Fix from $1,9502023-02-09 MEDIUM 5.5 CVE-2023-21422 Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server w… Android Mitigation only Fix from $1,6002023-02-09 HIGH 7.8 CVE-2023-23696 Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious user… Command \| Intel Vpro Out Of Band 4.4.0+ Fix from $1,9502023-02-07 CRITICAL 9.8 CVE-2022-3229EPSS 66% Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated a… Unified Remote after 3.11.0.2483 Fix from $2,3002023-02-06 HIGH 8.8 CVE-2022-24894 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse pr… Symfony 4.4.50 / 5.4.2+ Fix from $1,9502023-02-03 HIGH 7.8 CVE-2022-4062 A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets acces… Ecostruxure Power Commission 2.26+ Fix from $1,9502023-02-01 HIGH 7.3 CVE-2022-34405 An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit thi… Realtek High Definition Audio Driver 6.0.9254.1 / 6.0.9388.1+ Fix from $1,9502023-01-26