Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2023-38441

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

Mitigation only
Fix from $1,600 2023-09-04
Android MEDIUM 5.5
CVE-2023-38442

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

Mitigation only
Fix from $1,600 2023-09-04
Android HIGH 7.8
CVE-2023-38443

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileg…

Mitigation only
Fix from $1,950 2023-09-04
Android HIGH 7.8
CVE-2023-38444

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileg…

No fix yet
Fix from $1,950 2023-09-04
Android MEDIUM 5.5
CVE-2023-38445

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

No fix yet
Fix from $1,600 2023-09-04
Android MEDIUM 5.5
CVE-2023-38446

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

Mitigation only
Fix from $1,600 2023-09-04
Xwiki MEDIUM 6.3
CVE-2023-41046

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible in XWiki to execute Velocity …

Fix: 14.10.10 / 15.4+
Fix from $1,600 2023-09-01
Enterprise Server MEDIUM 5.3
CVE-2023-23763

An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access …

Fix: 3.6.18 / 3.7.16+
Fix from $1,600 2023-09-01
Bludit HIGH 7.8
CVE-2023-24674

Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

No fix yet
Fix from $1,950 2023-09-01
Agent MEDIUM 5.5
CVE-2023-41750

Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before buil…

Mitigation only
Fix from $1,600 2023-08-31
Spice Server HIGH 8.6
CVE-2020-23793

An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can res…

No fix yet
Fix from $1,950 2023-08-22
Inure MEDIUM 6.1
CVE-2023-4434

Missing Authorization in GitHub repository hamza417/inure prior to build88.

Patch available
Fix from $1,600 2023-08-20
Rikunabi Next MEDIUM 6.1
CVE-2023-39507

Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a malicious intent to lead the…

Fix: 11.5.0+
Fix from $1,600 2023-08-16
Keystone MEDIUM 5.3
CVE-2023-40027

Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as `undefined`, the `adminMeta` …

Fix: 5.5.1+
Fix from $1,600 2023-08-15
Contributor License Agreement Assistant HIGH 8.1
CVE-2023-39438

A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing spec…

Fix: 2.13.1+
Fix from $1,950 2023-08-15
Android MEDIUM 5.5
CVE-2023-21288

In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local …

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21234

In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to…

Mitigation only
Fix from $1,600 2023-08-14
Android MEDIUM 6.8
CVE-2023-21132

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This co…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 6.8
CVE-2023-21133

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This co…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 6.8
CVE-2023-21134

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This co…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 6.8
CVE-2023-21140

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This co…

Patch available
Fix from $1,600 2023-08-14
Mattermost MEDIUM 6.5
CVE-2023-4106

Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to …

Fix: 7.8.8 / 7.9.6+
Fix from $1,600 2023-08-11
1panel CRITICAL 9.8
CVE-2023-39966

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead …

No fix yet
Fix from $2,300 2023-08-10
OpenBSD MEDIUM 5.5
CVE-2023-40216

OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a…

Patch available
Fix from $1,600 2023-08-10
Wp 6070 Wvps Firmware HIGH 8.2
CVE-2023-37862

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP …

Fix: 4.0.10+
Fix from $1,950 2023-08-09
Wp 6070 Wvps Firmware HIGH 7.5
CVE-2023-37860

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of th…

Fix: 4.0.10+
Fix from $1,950 2023-08-09
Netweaver Application Server Abap MEDIUM 6.5
CVE-2023-37492

SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BAS…

Mitigation only
Fix from $1,600 2023-08-08
Android MEDIUM 5.5
CVE-2023-33906

In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privil…

Mitigation only
Fix from $1,600 2023-08-07
Android MEDIUM 5.5
CVE-2023-33907

In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privi…

Mitigation only
Fix from $1,600 2023-08-07
Android MEDIUM 5.5
CVE-2023-33908

In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

Mitigation only
Fix from $1,600 2023-08-07