Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.8 CVE-2023-50976 Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API. Redpanda 23.1.21 / 23.2.18+ Fix from $2,3002023-12-18 HIGH 8.8 CVE-2023-48375 SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perf… Cws Collaborative Development Platform Mitigation only Fix from $1,9502023-12-15 HIGH 7.1 CVE-2023-48676 Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agen… Agent Mitigation only Fix from $1,9502023-12-14 MEDIUM 5.4 CVE-2023-50767 Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request… Nexus Platform after 3.18.0-03 Fix from $1,6002023-12-13 HIGH 8.8 CVE-2023-47573 An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing a low-privileged u… Rely Pcie Firmware Mitigation only Fix from $1,9502023-12-13 CRITICAL 9.8 CVE-2023-48417 Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application Chromecast Firmware 2023-10-01+ Fix from $2,3002023-12-11 CRITICAL 9.1 CVE-2023-6394 A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati… Build Of Quarkus 3.6.0+ Fix from $2,3002023-12-09 HIGH 7.8 CVE-2023-48402 In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no addit… Android Mitigation only Fix from $1,9502023-12-08 HIGH 7.5 CVE-2023-39167 In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data. Senec Storage Box Firmware after 2023-06-19 Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-46354 In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information … Orders \(csv\, Excel\) Export Pro 5.2.0+ Fix from $1,9502023-12-06 HIGH 7.5 CVE-2023-44113 Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability… Emui No fix yet Fix from $1,9502023-12-06 HIGH 7.8 CVE-2023-40089 In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permissi… Android Patch available Fix from $1,9502023-12-04 HIGH 7.8 CVE-2023-40094 In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to… Android Patch available Fix from $1,9502023-12-04 MEDIUM 6.7 CVE-2023-32855 In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System e… Yocto Mitigation only Fix from $1,6002023-12-04 HIGH 7.8 CVE-2023-42748 In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi… Android No fix yet Fix from $1,9502023-12-04 MEDIUM 5.5 CVE-2023-42749 In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to lo… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42730 In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local infor… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42732 In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution priv… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42733 In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution priv… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42734 In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution priv… Android Mitigation only Fix from $1,6002023-12-04 HIGH 7.8 CVE-2023-42736 In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi… Android Mitigation only Fix from $1,9502023-12-04 MEDIUM 5.5 CVE-2023-42737 In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local i… Android Mitigation only Fix from $1,6002023-12-04 HIGH 7.8 CVE-2023-42738 In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi… Android Mitigation only Fix from $1,9502023-12-04 HIGH 7.8 CVE-2023-42739 In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to lo… Android Mitigation only Fix from $1,9502023-12-04 HIGH 7.8 CVE-2023-42740 In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local e… Android Mitigation only Fix from $1,9502023-12-04 MEDIUM 5.5 CVE-2023-42741 In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local i… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42742 In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed Android No fix yet Fix from $1,6002023-12-04 HIGH 7.8 CVE-2023-42743 In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi… Android No fix yet Fix from $1,9502023-12-04 MEDIUM 5.5 CVE-2023-42744 In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges … Android No fix yet Fix from $1,6002023-12-04 HIGH 7.8 CVE-2023-42745 In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi… Android No fix yet Fix from $1,9502023-12-04