Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2023-33909

In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privil…

Mitigation only
Fix from $1,600 2023-08-07
Android MEDIUM 5.5
CVE-2023-33910

In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privil…

Mitigation only
Fix from $1,600 2023-08-07
Android MEDIUM 5.5
CVE-2023-33911

In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileg…

Mitigation only
Fix from $1,600 2023-08-07
Android MEDIUM 5.5
CVE-2023-33912

In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privil…

Mitigation only
Fix from $1,600 2023-08-07
Metersphere HIGH 7.5
CVE-2023-38494

MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not ha…

Fix: 2.10.4+
Fix from $1,950 2023-08-04
Foundry Campaigns MEDIUM 5.9
CVE-2023-30950

The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint

Fix: 0.623.0+
Fix from $1,600 2023-08-03
Answer MEDIUM 6.5
CVE-2023-4124

Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.

Fix: 1.1.1+
Fix from $1,600 2023-08-03
Backup Migration MEDIUM 6.5
CVE-2023-0958

Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_instal…

Fix: 1.1.4 / 1.2.8+
Fix from $1,600 2023-07-28
Tolgee HIGH 8.1
CVE-2023-38510

Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request is made using an API key, the …

Fix: 3.23.1+
Fix from $1,950 2023-07-27
Instawp Connect CRITICAL 9.8
CVE-2023-3956

The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capabil…

Fix: after 0.0.9.18
Fix from $2,300 2023-07-27
Servicenow Devops HIGH 7.5
CVE-2023-3442

A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully…

Fix: 1.38.1+
Fix from $1,950 2023-07-26
Xperiencentral MEDIUM 6.5
CVE-2022-43712

POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are not logged in. If an unauthori…

Fix: after 10.36.0
Fix from $1,600 2023-07-26
Emlog MEDIUM 6.5
CVE-2023-37049

emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.

No fix yet
Fix from $1,600 2023-07-26
Color Laserjet Pro 4201 4203 4ra87f Firmware CRITICAL 9.8
CVE-2023-26301

Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege and/or Information Disclosure related to a lack of aut…

Fix: 6.12.1.12-202306030312+
Fix from $2,300 2023-07-21
Nomad MEDIUM 5.3
CVE-2023-3300

HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users …

Fix: after 1.5.6
Fix from $1,600 2023-07-20
Hazelcast HIGH 8.8
CVE-2023-33265

In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticat…

Fix: 5.0.5 / 5.1.7+
Fix from $1,950 2023-07-18
Profilegrid HIGH 8.8
CVE-2023-3713

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check…

Fix: after 5.5.1
Fix from $1,950 2023-07-18
Profilegrid HIGH 8.8
CVE-2023-3714

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler…

Fix: 5.5.3+
Fix from $1,950 2023-07-18
Plane HIGH 7.5
CVE-2023-2268

Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.

No fix yet
Fix from $1,950 2023-07-15
Android HIGH 7.8
CVE-2023-21257

In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission …

Patch available
Fix from $1,950 2023-07-13
Android HIGH 7.8
CVE-2023-21247

In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due t…

Patch available
Fix from $1,950 2023-07-13
Android HIGH 7.8
CVE-2023-21248

In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a m…

Patch available
Fix from $1,950 2023-07-13
Benchmark Evaluator MEDIUM 5.4
CVE-2023-37963

A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to connect to an att…

Fix: after 1.0.1
Fix from $1,600 2023-07-12
Elasticbox Ci HIGH 7.1
CVE-2023-37965

A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-…

Fix: after 5.0.1
Fix from $1,950 2023-07-12
Datadog MEDIUM 6.5
CVE-2023-37944

A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specif…

Fix: 5.4.2+
Fix from $1,600 2023-07-12
Orka By Macstadium HIGH 7.1
CVE-2023-37949

A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attac…

Fix: 1.34+
Fix from $1,950 2023-07-12
Mabl MEDIUM 6.5
CVE-2023-37953

A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifie…

Fix: after 0.0.46
Fix from $1,600 2023-07-12
Test Results Aggregator MEDIUM 6.5
CVE-2023-37956

A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Read permission to connect to a…

Fix: after 1.2.13
Fix from $1,600 2023-07-12
Sumologic Publisher MEDIUM 6.5
CVE-2023-37959

A missing permission check in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers with Overall/Read permission to connect to an att…

Fix: after 2.2.1
Fix from $1,600 2023-07-12
Android MEDIUM 5.5
CVE-2023-33889

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

No fix yet
Fix from $1,600 2023-07-12