Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.8 CVE-2023-21328 In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check.… Android 14.0+ Fix from $1,9502023-10-30 MEDIUM 5.5 CVE-2023-21329 In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local inf… Android 14.0+ Fix from $1,6002023-10-30 MEDIUM 5.5 CVE-2023-21340 In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no… Android 14.0+ Fix from $1,6002023-10-30 HIGH 7.8 CVE-2023-21341 In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation … Android 14.0+ Fix from $1,9502023-10-30 HIGH 7.8 CVE-2023-21313 In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalation of pr… Android 14.0+ Fix from $1,9502023-10-30 MEDIUM 5.5 CVE-2023-21321 In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclo… Android 14.0+ Fix from $1,6002023-10-30 HIGH 7.8 CVE-2021-39810 In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user … Android Mitigation only Fix from $1,9502023-10-30 MEDIUM 5.5 CVE-2023-21294 In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure wit… Android 14.0+ Fix from $1,6002023-10-30 MEDIUM 5.4 CVE-2023-5251 The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid… Grid Plus after 1.3.2 Fix from $1,6002023-10-30 HIGH 7.5 CVE-2023-5426 The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_d… Post Meta Data Manager 1.2.1+ Fix from $1,9502023-10-28 HIGH 8.8 CVE-2023-5425 The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_c… Post Meta Data Manager 1.2.1+ Fix from $1,9502023-10-28 MEDIUM 6.5 CVE-2023-30969 The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all… Tiles 4.326.0+ Fix from $1,6002023-10-26 HIGH 8.8 CVE-2023-5311 The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in … Wp Extra 6.3+ Fix from $1,9502023-10-25 HIGH 8.1 CVE-2023-4606 An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem… Thinkagile Hx5530 Firmware Mitigation only Fix from $1,9502023-10-25 HIGH 7.8 CVE-2023-43488 The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the… Ctrlx Hmi Web Panel Wr2107 Firmware Mitigation only Fix from $1,9502023-10-25 HIGH 8.1 CVE-2023-37910 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with the introduction of attachment… Xwiki 14.4.8 / 14.10.4+ Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-5132 The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the parseRemoteReq… Soisy Pagamento Rateale after 6.0.1 Fix from $1,9502023-10-21 CRITICAL 9.8 CVE-2023-5533 The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions… Wpbot after 4.8.9 Fix from $2,3002023-10-20 MEDIUM 5.3 CVE-2023-3869 The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment functi… Wpdiscuz after 7.6.3 Fix from $1,6002023-10-20 MEDIUM 5.3 CVE-2023-3998 The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in… Wpdiscuz after 7.6.3 Fix from $1,6002023-10-20 HIGH 7.5 CVE-2023-4668 The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe… Ad Inserter 2.7.31+ Fix from $1,9502023-10-20 MEDIUM 5.3 CVE-2022-4943 The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plug… Google Authenticator after 5.6.5 Fix from $1,6002023-10-20 HIGH 8.8 CVE-2020-36698 The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. … Security \& Malware Scan 2.51+ Fix from $1,9502023-10-20 MEDIUM 5.3 CVE-2021-4353 The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including,… Woocommerce Dynamic Pricing \& Discounts 2.4.2+ Fix from $1,6002023-10-20 HIGH 7.8 CVE-2023-27792 An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories. Easyinstall No fix yet Fix from $1,9502023-10-19 MEDIUM 5.3 CVE-2023-4645 The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This… Ad Inserter after 2.7.30 Fix from $1,6002023-10-19 MEDIUM 5.4 CVE-2023-42473 S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalat… S\/4hana Mitigation only Fix from $1,6002023-10-10 MEDIUM 6.5 CVE-2022-36228 Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any device and set the device passwo… Noke Standard Smart Padlock Firmware No fix yet Fix from $1,6002023-10-09 HIGH 7.5 CVE-2023-43700 Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authenticatio… Apu0200 Firmware 4.0.0.6+ Fix from $1,9502023-10-09 HIGH 7.1 CVE-2023-45247 Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agen… Agent Mitigation only Fix from $1,9502023-10-09