Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Agent MEDIUM 5.5
CVE-2023-45242

Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, …

Mitigation only
Fix from $1,600 2023-10-05
Agent MEDIUM 5.5
CVE-2023-45243

Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, …

Mitigation only
Fix from $1,600 2023-10-05
Agent MEDIUM 5.5
CVE-2023-44210

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agen…

Patch available
Fix from $1,600 2023-10-04
Urbancode Deploy MEDIUM 6.5
CVE-2023-40376

IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated use…

Fix: after 7.3.2.0
Fix from $1,600 2023-10-04
Cyber Protect Home Office CRITICAL 9.1
CVE-2023-44208

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Offic…

Fix: 40713+
Fix from $2,300 2023-10-04
Wp Mail Smtp MEDIUM 5.3
CVE-2023-3213

The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page functio…

Fix: after 3.8.0
Fix from $1,600 2023-10-04
Inure MEDIUM 5.5
CVE-2023-5321

Missing Authorization in GitHub repository hamza417/inure prior to build94.

Patch available
Fix from $1,600 2023-09-30
Jumpserver CRITICAL 9.1
CVE-2023-43652

JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH publ…

Fix: 2.28.20 / 3.7.1+
Fix from $2,300 2023-09-27
Catalyst Sd Wan Manager CRITICAL 9.8
CVE-2023-20252

A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remot…

Mitigation only
Fix from $2,300 2023-09-27
Apicast HIGH 7.5
CVE-2023-0456

A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul…

Fix: 2.12.2 / 2.13.2+
Fix from $1,950 2023-09-27
Docker Desktop HIGH 8.8
CVE-2023-5165

Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains …

Fix: 4.23.0+
Fix from $1,950 2023-09-25
Emui CRITICAL 9.1
CVE-2023-41296

Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.

No fix yet
Fix from $2,300 2023-09-25
Fedora MEDIUM 5.5
CVE-2023-43090

A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop sessio…

Fix: 43.9 / 44.5+
Fix from $1,600 2023-09-22
Tl Er5120g Firmware CRITICAL 9.8
CVE-2023-43135

There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive inform…

No fix yet
Fix from $2,300 2023-09-20
360r Firmware CRITICAL 9.8
CVE-2023-43134

There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device wit…

No fix yet
Fix from $2,300 2023-09-20
Build Failure Analyzer MEDIUM 6.5
CVE-2023-43501

A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read permission to connect to an …

Fix: 2.4.2+
Fix from $1,600 2023-09-20
Super Store Finder MEDIUM 5.3
CVE-2023-5054

The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9…

Fix: after 6.9.2
Fix from $1,600 2023-09-19
Openshift Data Science CRITICAL 9.8
CVE-2023-0923

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making …

Fix: 1.22.1-3+
Fix from $2,300 2023-09-15
Snmp Web Pro CRITICAL 9.8
CVE-2023-39073

An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.

No fix yet
Fix from $2,300 2023-09-12
S4core MEDIUM 5.4
CVE-2023-40625

S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated …

Mitigation only
Fix from $1,600 2023-09-12
Android MEDIUM 5.5
CVE-2023-35677

In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to loca…

Mitigation only
Fix from $1,600 2023-09-11
Android HIGH 7.8
CVE-2023-35665

In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalati…

Patch available
Fix from $1,950 2023-09-11
Cleaning Business Software CRITICAL 9.8
CVE-2023-36140

In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.

Mitigation only
Fix from $2,300 2023-09-11
Vpn MEDIUM 5.5
CVE-2023-4104

An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN se…

Fix: 2.16.1+
Fix from $1,600 2023-09-11
Higrade MEDIUM 5.3
CVE-2023-40040

An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacker can start the camera feed v…

Mitigation only
Fix from $1,600 2023-09-11
Aws Codecommit Trigger MEDIUM 6.5
CVE-2023-41943

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Rea…

Fix: after 3.0.12
Fix from $1,600 2023-09-06
Assembla Auth HIGH 8.8
CVE-2023-41945

Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to…

Fix: after 1.14
Fix from $1,950 2023-09-06
Cerebrate MEDIUM 5.3
CVE-2023-41908

Cerebrate before 1.15 lacks the Secure attribute for the session cookie.

Fix: 1.15+
Fix from $1,600 2023-09-05
Android MEDIUM 5.5
CVE-2023-20825

In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no a…

Mitigation only
Fix from $1,600 2023-09-04
Android MEDIUM 5.5
CVE-2023-20826

In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additio…

Mitigation only
Fix from $1,600 2023-09-04