Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.5 CVE-2023-42703 In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local … Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42704 In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42671 In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42672 In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42673 In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42674 In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42675 In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42676 In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42677 In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform… Android Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-42678 In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform… Android Mitigation only Fix from $1,6002023-12-04 HIGH 7.8 CVE-2023-42681 In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privilege… Android Mitigation only Fix from $1,9502023-12-04 HIGH 8.8 CVE-2023-47870 Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Access… Wpforo Forum after 2.2.6 Fix from $1,9502023-11-30 MEDIUM 6.5 CVE-2023-49620 Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), … Dolphinscheduler 3.1.0+ Fix from $1,6002023-11-30 CRITICAL 9.8 CVE-2023-49654 Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller f… Matlab 2.11.1+ Fix from $2,3002023-11-29 MEDIUM 5.3 CVE-2023-5611 The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, al… Seraphinite Accelerator 2.20.32+ Fix from $1,6002023-11-27 HIGH 7.5 CVE-2023-30581 The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outside of the policy.json definit… Node.js 16.20.1 / 18.16.1+ Fix from $1,9502023-11-23 MEDIUM 6.5 CVE-2023-6007 The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check o… Userpro after 5.1.1 Fix from $1,6002023-11-22 MEDIUM 5.3 CVE-2023-2448 The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'userpro_shortcode_template' f… Userpro after 5.1.4 Fix from $1,6002023-11-22 HIGH 8.8 CVE-2023-47757 Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead … Aweber 7.3.10+ Fix from $1,9502023-11-17 HIGH 8.8 CVE-2023-39544 CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSaf… Expresscluster X Patch available Fix from $1,9502023-11-17 MEDIUM 5.4 CVE-2023-48222 Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in bot… Rundeck 4.17.3+ Fix from $1,6002023-11-16 HIGH 7.5 CVE-2023-6020EPSS 15% LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication. Ray No fix yet Fix from $1,9502023-11-16 HIGH 7.5 CVE-2023-6038 A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the ser… H2o No fix yet Fix from $1,9502023-11-16 MEDIUM 5.3 CVE-2023-4723 The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the aj… Elementor Addon Elements after 1.12.7 Fix from $1,6002023-11-15 HIGH 7.5 CVE-2023-6001 Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment. Yugabytedb 2.18.4.0+ Fix from $1,9502023-11-08 HIGH 8.1 CVE-2023-43885 Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the dev… Rx9 Pro Firmware No fix yet Fix from $1,9502023-11-07 HIGH 7.5 CVE-2023-5454 The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users t… Templately 2.2.6+ Fix from $1,9502023-11-06 MEDIUM 6.5 CVE-2023-4700 An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed … GitLab 16.3.6 / 16.4.2+ Fix from $1,6002023-11-06 CRITICAL 9.1 CVE-2023-36621 An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictio… Boomerang 13.83+ Fix from $2,3002023-11-03 MEDIUM 5.3 CVE-2023-43194 Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter. Submitty Patch available Fix from $1,6002023-11-02