Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Sealos HIGH 8.1
CVE-2023-36815

Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sea…

Fix: after 4.2.0
Fix from $1,950 2023-07-03
Opal Estate MEDIUM 5.3
CVE-2021-4388

The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missin…

Fix: after 1.6.11
Fix from $1,600 2023-07-01
Node.js HIGH 7.5
CVE-2023-30586

A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is en…

Fix: 20.3.1+
Fix from $1,950 2023-07-01
Sg 2404 Mr Firmware HIGH 7.5
CVE-2023-36144EPSS 37%

An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the dev…

No fix yet
Fix from $1,950 2023-06-30
Tbox Ms Cpu32 Firmware MEDIUM 5.3
CVE-2023-36607

The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information…

Fix: after 1.50.598
Fix from $1,600 2023-06-29
Android MEDIUM 5.5
CVE-2023-21173

In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. …

Mitigation only
Fix from $1,600 2023-06-28
Android MEDIUM 5.5
CVE-2023-21177

In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing per…

Mitigation only
Fix from $1,600 2023-06-28
Android HIGH 7.8
CVE-2023-21185

In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalation of privilege from the gues…

Mitigation only
Fix from $1,950 2023-06-28
Android HIGH 7.8
CVE-2023-21149

In registerGsmaServiceIntentReceiver of ShannonRcsService.java, there is a possible way to activate/deactivate RCS service due to a missing permissio…

Mitigation only
Fix from $1,950 2023-06-28
Insider Threat Management Server MEDIUM 6.5
CVE-2023-36000

A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an a…

Fix: 7.14.3+
Fix from $1,600 2023-06-27
Dataease MEDIUM 6.5
CVE-2023-35164

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing aut…

Fix: 1.18.8+
Fix from $1,600 2023-06-26
Dataease HIGH 8.1
CVE-2023-34463

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized …

Fix: 1.18.8+
Fix from $1,950 2023-06-26
Codekop HIGH 8.8
CVE-2023-36348EPSS 6%

POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.

No fix yet
Fix from $1,950 2023-06-23
Bigfix Webui Insights MEDIUM 6.5
CVE-2023-23344

A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.

Mitigation only
Fix from $1,600 2023-06-23
Masterstudy Lms MEDIUM 6.5
CVE-2023-35093

Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions al…

Fix: after 3.0.8
Fix from $1,600 2023-06-22
Emui MEDIUM 5.3
CVE-2022-48491

Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead to ads and other windows to d…

Mitigation only
Fix from $1,600 2023-06-19
Easy Media Replace HIGH 8.1
CVE-2022-46850

Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin <= 0.1.3 versions.

Fix: after 0.1.3
Fix from $1,950 2023-06-19
Mattermost MEDIUM 6.5
CVE-2023-2784

Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install…

Fix: after 7.9.3
Fix from $1,600 2023-06-16
Mattermost MEDIUM 6.5
CVE-2023-2787

Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message thre…

Fix: after 7.9.3
Fix from $1,600 2023-06-16
Mattermost MEDIUM 6.5
CVE-2023-2788

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persi…

Fix: after 7.9.3
Fix from $1,600 2023-06-16
Harmonyos MEDIUM 5.3
CVE-2023-34165

Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-pa…

Mitigation only
Fix from $1,600 2023-06-16
Android MEDIUM 5.5
CVE-2023-21141

In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local …

Patch available
Fix from $1,600 2023-06-15
Android HIGH 7.8
CVE-2023-21122

In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing per…

Mitigation only
Fix from $1,950 2023-06-15
Android HIGH 7.8
CVE-2023-21123

In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing p…

Mitigation only
Fix from $1,950 2023-06-15
Digital.ai App Management Publisher MEDIUM 6.5
CVE-2023-35149

A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to con…

Fix: after 2.6
Fix from $1,600 2023-06-14
Fossbilling HIGH 7.5
CVE-2023-3230

Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.

Fix: 0.5.0+
Fix from $1,950 2023-06-14
Wp Directory Kit MEDIUM 5.3
CVE-2023-2280

The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on th…

Fix: 1.2.3+
Fix from $1,600 2023-06-09
Woocommerce Multivendor Marketplace MEDIUM 5.4
CVE-2023-2275

The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a mi…

Fix: after 1.5.3
Fix from $1,600 2023-06-09
Metform Elementor Contact Form Builder MEDIUM 5.3
CVE-2023-1843

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability …

Fix: after 3.3.0
Fix from $1,600 2023-06-09
Quiz And Survey Master CRITICAL 9.1
CVE-2023-0291

The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the …

Fix: after 8.0.8
Fix from $2,300 2023-06-09