Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2023-42703

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local …

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42704

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42671

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42672

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42673

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42674

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42675

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42676

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42677

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-12-04
Android MEDIUM 5.5
CVE-2023-42678

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-12-04
Android HIGH 7.8
CVE-2023-42681

In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privilege…

Mitigation only
Fix from $1,950 2023-12-04
Wpforo Forum HIGH 8.8
CVE-2023-47870

Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Access…

Fix: after 2.2.6
Fix from $1,950 2023-11-30
Dolphinscheduler MEDIUM 6.5
CVE-2023-49620

Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), …

Fix: 3.1.0+
Fix from $1,600 2023-11-30
Matlab CRITICAL 9.8
CVE-2023-49654

Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller f…

Fix: 2.11.1+
Fix from $2,300 2023-11-29
Seraphinite Accelerator MEDIUM 5.3
CVE-2023-5611

The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, al…

Fix: 2.20.32+
Fix from $1,600 2023-11-27
Node.js HIGH 7.5
CVE-2023-30581

The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outside of the policy.json definit…

Fix: 16.20.1 / 18.16.1+
Fix from $1,950 2023-11-23
Userpro MEDIUM 6.5
CVE-2023-6007

The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check o…

Fix: after 5.1.1
Fix from $1,600 2023-11-22
Userpro MEDIUM 5.3
CVE-2023-2448

The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'userpro_shortcode_template' f…

Fix: after 5.1.4
Fix from $1,600 2023-11-22
Aweber HIGH 8.8
CVE-2023-47757

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead …

Fix: 7.3.10+
Fix from $1,950 2023-11-17
Expresscluster X HIGH 8.8
CVE-2023-39544

CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSaf…

Patch available
Fix from $1,950 2023-11-17
Rundeck MEDIUM 5.4
CVE-2023-48222

Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in bot…

Fix: 4.17.3+
Fix from $1,600 2023-11-16
Ray HIGH 7.5
CVE-2023-6020EPSS 15%

LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.

No fix yet
Fix from $1,950 2023-11-16
H2o HIGH 7.5
CVE-2023-6038

A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the ser…

No fix yet
Fix from $1,950 2023-11-16
Elementor Addon Elements MEDIUM 5.3
CVE-2023-4723

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the aj…

Fix: after 1.12.7
Fix from $1,600 2023-11-15
Yugabytedb HIGH 7.5
CVE-2023-6001

Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.

Fix: 2.18.4.0+
Fix from $1,950 2023-11-08
Rx9 Pro Firmware HIGH 8.1
CVE-2023-43885

Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the dev…

No fix yet
Fix from $1,950 2023-11-07
Templately HIGH 7.5
CVE-2023-5454

The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users t…

Fix: 2.2.6+
Fix from $1,950 2023-11-06
GitLab MEDIUM 6.5
CVE-2023-4700

An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed …

Fix: 16.3.6 / 16.4.2+
Fix from $1,600 2023-11-06
Boomerang CRITICAL 9.1
CVE-2023-36621

An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictio…

Fix: 13.83+
Fix from $2,300 2023-11-03
Submitty MEDIUM 5.3
CVE-2023-43194

Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.

Patch available
Fix from $1,600 2023-11-02