Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Kanboard MEDIUM 5.4
CVE-2023-33968

Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to a missing access …

Fix: 1.2.30+
Fix from $1,600 2023-06-05
Kanboard MEDIUM 6.5
CVE-2023-33970

Kanboard is open source project management software that focuses on the Kanban methodology. A vulnerability related to a `missing access control` was…

Fix: 1.2.30+
Fix from $1,600 2023-06-05
Online Booking \& Scheduling Calendar MEDIUM 5.3
CVE-2023-2299

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-jso…

Fix: after 4.2.10
Fix from $1,600 2023-06-03
Online Booking \& Scheduling Calendar MEDIUM 5.4
CVE-2023-2415

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a miss…

Fix: after 4.2.10
Fix from $1,600 2023-06-03
Conprosys Hmi System HIGH 8.8
CVE-2023-28657

Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC where the affected product is in…

Fix: 3.5.3+
Fix from $1,950 2023-06-01
Feather Login Page HIGH 8.8
CVE-2023-2545

The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' fu…

Fix: after 1.1.1
Fix from $1,950 2023-05-31
Feather Login Page MEDIUM 5.4
CVE-2023-2547

The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteUser' function…

Fix: after 1.1.1
Fix from $1,600 2023-05-31
Openemr MEDIUM 5.4
CVE-2023-2945

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.

Fix: 7.0.1+
Fix from $1,600 2023-05-27
Synapse MEDIUM 5.0
CVE-2022-39335

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers …

Fix: 1.69.0+
Fix from $1,600 2023-05-26
M Files HIGH 7.8
CVE-2023-2480

Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension…

Fix: 23.5.12598.0+
Fix from $1,950 2023-05-25
Briar HIGH 7.4
CVE-2023-33983

The Introduction Client in Briar through 1.5.3 does not implement out-of-band verification for the public keys of introducees. An introducer can laun…

Fix: after 1.5.3
Fix from $1,950 2023-05-24
Digital Experience Platform HIGH 7.5
CVE-2023-33948

The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downlo…

Mitigation only
Fix from $1,950 2023-05-24
Go Pricing HIGH 8.8
CVE-2023-2494

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil…

Fix: after 3.3.19
Fix from $1,950 2023-05-24
Nevado Jms HIGH 7.8
CVE-2023-31826

Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary comman…

No fix yet
Fix from $1,950 2023-05-23
Snarkjs HIGH 7.5
CVE-2023-33252

iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.

Fix: after 0.6.11
Fix from $1,950 2023-05-21
Groundhogg MEDIUM 5.4
CVE-2023-2716

The Groundhogg plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'a…

Fix: after 2.7.9.8
Fix from $1,600 2023-05-20
Waiting MEDIUM 5.4
CVE-2023-2757

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' function…

Fix: after 0.6.2
Fix from $1,600 2023-05-18
S4core MEDIUM 5.5
CVE-2023-32112

Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SA…

Mitigation only
Fix from $1,600 2023-05-09
Android HIGH 7.8
CVE-2022-48368

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

Mitigation only
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-48369

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

Mitigation only
Fix from $1,950 2023-05-09
Android MEDIUM 5.5
CVE-2022-48370

In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privile…

Mitigation only
Fix from $1,600 2023-05-09
Android MEDIUM 5.5
CVE-2022-48371

In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privile…

Mitigation only
Fix from $1,600 2023-05-09
Android MEDIUM 5.5
CVE-2022-48375

In contacts service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

Mitigation only
Fix from $1,600 2023-05-09
Android MEDIUM 5.5
CVE-2022-48376

In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

Mitigation only
Fix from $1,600 2023-05-09
Android MEDIUM 5.5
CVE-2022-48377

In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

Mitigation only
Fix from $1,600 2023-05-09
Android MEDIUM 5.5
CVE-2022-48378

In engineermode service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privil…

Mitigation only
Fix from $1,600 2023-05-09
Android MEDIUM 5.5
CVE-2022-48379

In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

Mitigation only
Fix from $1,600 2023-05-09
Android HIGH 7.8
CVE-2022-48383

.In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

Mitigation only
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-48384

In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileg…

Mitigation only
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-48388

In powerEx service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi…

No fix yet
Fix from $1,950 2023-05-09