Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Nomad HIGH 8.8
CVE-2023-1299

HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fix…

Mitigation only
Fix from $1,950 2023-03-14
Ruggedcom Crossbow HIGH 8.8
CVE-2023-27309

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check …

Fix: 5.2+
Fix from $1,950 2023-03-14
Ruggedcom Crossbow HIGH 8.8
CVE-2023-27310

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check …

Fix: 5.2+
Fix from $1,950 2023-03-14
Digital Experience Platform CRITICAL 9.8
CVE-2022-48367

An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.

Fix: 1.1.9 / 1.3.17+
Fix from $2,300 2023-03-12
Android MEDIUM 5.5
CVE-2022-47478

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47479

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

No fix yet
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47480

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47481

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47482

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47483

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47484

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi…

No fix yet
Fix from $1,600 2023-03-10
Android MEDIUM 6.7
CVE-2022-47461

In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

No fix yet
Fix from $1,600 2023-03-10
Android MEDIUM 6.7
CVE-2022-47462

In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47471

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47472

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47473

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47474

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47475

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47476

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2023-03-10
Android MEDIUM 5.5
CVE-2022-47477

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2023-03-10
Onekeyadmin CRITICAL 9.1
CVE-2023-26957

onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.

No fix yet
Fix from $2,300 2023-03-09
Metersphere HIGH 7.5
CVE-2023-25573EPSS 52%

metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/downl…

Fix: 1.20.19+
Fix from $1,950 2023-03-09
Nex Forms MEDIUM 6.3
CVE-2020-36670

The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to m…

Fix: after 7.7.1
Fix from $1,600 2023-03-07
The Plus Addons For Elementor HIGH 8.8
CVE-2021-4331

The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free…

Fix: after 4.1.9
Fix from $1,950 2023-03-07
Jetbackup MEDIUM 5.4
CVE-2020-36667

The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes in versions up to, and inclu…

Fix: after 1.4.1
Fix from $1,600 2023-03-07
Blogengine.net MEDIUM 5.3
CVE-2023-22858

An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.

Mitigation only
Fix from $1,600 2023-03-06
Ghost MEDIUM 5.7
CVE-2023-26510

Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in …

Mitigation only
Fix from $1,600 2023-03-05
E Belediye CRITICAL 9.8
CVE-2023-1114

Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.10…

Fix: 1.0.0.100+
Fix from $2,300 2023-03-01
Mattermost MEDIUM 6.5
CVE-2023-27263

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team…

Fix: after 7.1.4
Fix from $1,600 2023-02-27
Mattermost MEDIUM 6.5
CVE-2023-27264

A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks…

Fix: after 7.1.4
Fix from $1,600 2023-02-27