Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Redpanda CRITICAL 9.8
CVE-2023-50976

Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.

Fix: 23.1.21 / 23.2.18+
Fix from $2,300 2023-12-18
Cws Collaborative Development Platform HIGH 8.8
CVE-2023-48375

SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perf…

Mitigation only
Fix from $1,950 2023-12-15
Agent HIGH 7.1
CVE-2023-48676

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agen…

Mitigation only
Fix from $1,950 2023-12-14
Nexus Platform MEDIUM 5.4
CVE-2023-50767

Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request…

Fix: after 3.18.0-03
Fix from $1,600 2023-12-13
Rely Pcie Firmware HIGH 8.8
CVE-2023-47573

An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing a low-privileged u…

Mitigation only
Fix from $1,950 2023-12-13
Chromecast Firmware CRITICAL 9.8
CVE-2023-48417

Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application

Fix: 2023-10-01+
Fix from $2,300 2023-12-11
Build Of Quarkus CRITICAL 9.1
CVE-2023-6394

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati…

Fix: 3.6.0+
Fix from $2,300 2023-12-09
Android HIGH 7.8
CVE-2023-48402

In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no addit…

Mitigation only
Fix from $1,950 2023-12-08
Senec Storage Box Firmware HIGH 7.5
CVE-2023-39167

In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.

Fix: after 2023-06-19
Fix from $1,950 2023-12-07
Orders \(csv\, Excel\) Export Pro HIGH 7.5
CVE-2023-46354

In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information …

Fix: 5.2.0+
Fix from $1,950 2023-12-06
Emui HIGH 7.5
CVE-2023-44113

Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability…

No fix yet
Fix from $1,950 2023-12-06
Android HIGH 7.8
CVE-2023-40089

In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permissi…

Patch available
Fix from $1,950 2023-12-04
Android HIGH 7.8
CVE-2023-40094

In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to…

Patch available
Fix from $1,950 2023-12-04
Yocto MEDIUM 6.7
CVE-2023-32855

In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System e…

Mitigation only
Fix from $1,600 2023-12-04
Android HIGH 7.8
CVE-2023-42748

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi…

No fix yet
Fix from $1,950 2023-12-04
Android MEDIUM 5.5
CVE-2023-42749

In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to lo…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42730

In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local infor…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42732

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution priv…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42733

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution priv…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42734

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution priv…

Mitigation only
Fix from $1,600 2023-12-04
Android HIGH 7.8
CVE-2023-42736

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi…

Mitigation only
Fix from $1,950 2023-12-04
Android MEDIUM 5.5
CVE-2023-42737

In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local i…

Mitigation only
Fix from $1,600 2023-12-04
Android HIGH 7.8
CVE-2023-42738

In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi…

Mitigation only
Fix from $1,950 2023-12-04
Android HIGH 7.8
CVE-2023-42739

In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to lo…

Mitigation only
Fix from $1,950 2023-12-04
Android HIGH 7.8
CVE-2023-42740

In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local e…

Mitigation only
Fix from $1,950 2023-12-04
Android MEDIUM 5.5
CVE-2023-42741

In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local i…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42742

In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed

No fix yet
Fix from $1,600 2023-12-04
Android HIGH 7.8
CVE-2023-42743

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi…

No fix yet
Fix from $1,950 2023-12-04
Android MEDIUM 5.5
CVE-2023-42744

In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges …

No fix yet
Fix from $1,600 2023-12-04
Android HIGH 7.8
CVE-2023-42745

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi…

No fix yet
Fix from $1,950 2023-12-04