Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.5 CVE-2023-45242 Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, … Agent Mitigation only Fix from $1,6002023-10-05 MEDIUM 5.5 CVE-2023-45243 Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, … Agent Mitigation only Fix from $1,6002023-10-05 MEDIUM 5.5 CVE-2023-44210 Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agen… Agent Patch available Fix from $1,6002023-10-04 MEDIUM 6.5 CVE-2023-40376 IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated use… Urbancode Deploy after 7.3.2.0 Fix from $1,6002023-10-04 CRITICAL 9.1 CVE-2023-44208 Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Offic… Cyber Protect Home Office 40713+ Fix from $2,3002023-10-04 MEDIUM 5.3 CVE-2023-3213 The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page functio… Wp Mail Smtp after 3.8.0 Fix from $1,6002023-10-04 MEDIUM 5.5 CVE-2023-5321 Missing Authorization in GitHub repository hamza417/inure prior to build94. Inure Patch available Fix from $1,6002023-09-30 CRITICAL 9.1 CVE-2023-43652 JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH publ… Jumpserver 2.28.20 / 3.7.1+ Fix from $2,3002023-09-27 CRITICAL 9.8 CVE-2023-20252 A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remot… Catalyst Sd Wan Manager Mitigation only Fix from $2,3002023-09-27 HIGH 7.5 CVE-2023-0456 A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul… Apicast 2.12.2 / 2.13.2+ Fix from $1,9502023-09-27 HIGH 8.8 CVE-2023-5165 Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains … Docker Desktop 4.23.0+ Fix from $1,9502023-09-25 CRITICAL 9.1 CVE-2023-41296 Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality. Emui No fix yet Fix from $2,3002023-09-25 MEDIUM 5.5 CVE-2023-43090 A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop sessio… Fedora 43.9 / 44.5+ Fix from $1,6002023-09-22 CRITICAL 9.8 CVE-2023-43135 There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive inform… Tl Er5120g Firmware No fix yet Fix from $2,3002023-09-20 CRITICAL 9.8 CVE-2023-43134 There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device wit… 360r Firmware No fix yet Fix from $2,3002023-09-20 MEDIUM 6.5 CVE-2023-43501 A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read permission to connect to an … Build Failure Analyzer 2.4.2+ Fix from $1,6002023-09-20 MEDIUM 5.3 CVE-2023-5054 The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9… Super Store Finder after 6.9.2 Fix from $1,6002023-09-19 CRITICAL 9.8 CVE-2023-0923 A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making … Openshift Data Science 1.22.1-3+ Fix from $2,3002023-09-15 CRITICAL 9.8 CVE-2023-39073 An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request. Snmp Web Pro No fix yet Fix from $2,3002023-09-12 MEDIUM 5.4 CVE-2023-40625 S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated … S4core Mitigation only Fix from $1,6002023-09-12 MEDIUM 5.5 CVE-2023-35677 In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to loca… Android Mitigation only Fix from $1,6002023-09-11 HIGH 7.8 CVE-2023-35665 In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalati… Android Patch available Fix from $1,9502023-09-11 CRITICAL 9.8 CVE-2023-36140 In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts. Cleaning Business Software Mitigation only Fix from $2,3002023-09-11 MEDIUM 5.5 CVE-2023-4104 An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN se… Vpn 2.16.1+ Fix from $1,6002023-09-11 MEDIUM 5.3 CVE-2023-40040 An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacker can start the camera feed v… Higrade Mitigation only Fix from $1,6002023-09-11 MEDIUM 6.5 CVE-2023-41943 Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Rea… Aws Codecommit Trigger after 3.0.12 Fix from $1,6002023-09-06 HIGH 8.8 CVE-2023-41945 Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to… Assembla Auth after 1.14 Fix from $1,9502023-09-06 MEDIUM 5.3 CVE-2023-41908 Cerebrate before 1.15 lacks the Secure attribute for the session cookie. Cerebrate 1.15+ Fix from $1,6002023-09-05 MEDIUM 5.5 CVE-2023-20825 In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no a… Android Mitigation only Fix from $1,6002023-09-04 MEDIUM 5.5 CVE-2023-20826 In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additio… Android Mitigation only Fix from $1,6002023-09-04