Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android HIGH 7.8
CVE-2023-21328

In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check.…

Fix: 14.0+
Fix from $1,950 2023-10-30
Android MEDIUM 5.5
CVE-2023-21329

In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local inf…

Fix: 14.0+
Fix from $1,600 2023-10-30
Android MEDIUM 5.5
CVE-2023-21340

In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no…

Fix: 14.0+
Fix from $1,600 2023-10-30
Android HIGH 7.8
CVE-2023-21341

In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation …

Fix: 14.0+
Fix from $1,950 2023-10-30
Android HIGH 7.8
CVE-2023-21313

In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalation of pr…

Fix: 14.0+
Fix from $1,950 2023-10-30
Android MEDIUM 5.5
CVE-2023-21321

In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclo…

Fix: 14.0+
Fix from $1,600 2023-10-30
Android HIGH 7.8
CVE-2021-39810

In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user …

Mitigation only
Fix from $1,950 2023-10-30
Android MEDIUM 5.5
CVE-2023-21294

In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure wit…

Fix: 14.0+
Fix from $1,600 2023-10-30
Grid Plus MEDIUM 5.4
CVE-2023-5251

The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid…

Fix: after 1.3.2
Fix from $1,600 2023-10-30
Post Meta Data Manager HIGH 7.5
CVE-2023-5426

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_d…

Fix: 1.2.1+
Fix from $1,950 2023-10-28
Post Meta Data Manager HIGH 8.8
CVE-2023-5425

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_c…

Fix: 1.2.1+
Fix from $1,950 2023-10-28
Tiles MEDIUM 6.5
CVE-2023-30969

The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all…

Fix: 4.326.0+
Fix from $1,600 2023-10-26
Wp Extra HIGH 8.8
CVE-2023-5311

The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in …

Fix: 6.3+
Fix from $1,950 2023-10-25
Thinkagile Hx5530 Firmware HIGH 8.1
CVE-2023-4606

An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem…

Mitigation only
Fix from $1,950 2023-10-25
Ctrlx Hmi Web Panel Wr2107 Firmware HIGH 7.8
CVE-2023-43488

The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the…

Mitigation only
Fix from $1,950 2023-10-25
Xwiki HIGH 8.1
CVE-2023-37910

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with the introduction of attachment…

Fix: 14.4.8 / 14.10.4+
Fix from $1,950 2023-10-25
Soisy Pagamento Rateale HIGH 7.5
CVE-2023-5132

The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the parseRemoteReq…

Fix: after 6.0.1
Fix from $1,950 2023-10-21
Wpbot CRITICAL 9.8
CVE-2023-5533

The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions…

Fix: after 4.8.9
Fix from $2,300 2023-10-20
Wpdiscuz MEDIUM 5.3
CVE-2023-3869

The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment functi…

Fix: after 7.6.3
Fix from $1,600 2023-10-20
Wpdiscuz MEDIUM 5.3
CVE-2023-3998

The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in…

Fix: after 7.6.3
Fix from $1,600 2023-10-20
Ad Inserter HIGH 7.5
CVE-2023-4668

The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe…

Fix: 2.7.31+
Fix from $1,950 2023-10-20
Google Authenticator MEDIUM 5.3
CVE-2022-4943

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plug…

Fix: after 5.6.5
Fix from $1,600 2023-10-20
Security \& Malware Scan HIGH 8.8
CVE-2020-36698

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. …

Fix: 2.51+
Fix from $1,950 2023-10-20
Woocommerce Dynamic Pricing \& Discounts MEDIUM 5.3
CVE-2021-4353

The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including,…

Fix: 2.4.2+
Fix from $1,600 2023-10-20
Easyinstall HIGH 7.8
CVE-2023-27792

An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories.

No fix yet
Fix from $1,950 2023-10-19
Ad Inserter MEDIUM 5.3
CVE-2023-4645

The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This…

Fix: after 2.7.30
Fix from $1,600 2023-10-19
S\/4hana MEDIUM 5.4
CVE-2023-42473

S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalat…

Mitigation only
Fix from $1,600 2023-10-10
Noke Standard Smart Padlock Firmware MEDIUM 6.5
CVE-2022-36228

Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any device and set the device passwo…

No fix yet
Fix from $1,600 2023-10-09
Apu0200 Firmware HIGH 7.5
CVE-2023-43700

Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authenticatio…

Fix: 4.0.0.6+
Fix from $1,950 2023-10-09
Agent HIGH 7.1
CVE-2023-45247

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agen…

Mitigation only
Fix from $1,950 2023-10-09