Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.5 CVE-2023-38441 In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges Android Mitigation only Fix from $1,6002023-09-04 MEDIUM 5.5 CVE-2023-38442 In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges Android Mitigation only Fix from $1,6002023-09-04 HIGH 7.8 CVE-2023-38443 In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileg… Android Mitigation only Fix from $1,9502023-09-04 HIGH 7.8 CVE-2023-38444 In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileg… Android No fix yet Fix from $1,9502023-09-04 MEDIUM 5.5 CVE-2023-38445 In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges Android No fix yet Fix from $1,6002023-09-04 MEDIUM 5.5 CVE-2023-38446 In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges Android Mitigation only Fix from $1,6002023-09-04 MEDIUM 6.3 CVE-2023-41046 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible in XWiki to execute Velocity … Xwiki 14.10.10 / 15.4+ Fix from $1,6002023-09-01 MEDIUM 5.3 CVE-2023-23763 An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access … Enterprise Server 3.6.18 / 3.7.16+ Fix from $1,6002023-09-01 HIGH 7.8 CVE-2023-24674 Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter. Bludit No fix yet Fix from $1,9502023-09-01 MEDIUM 5.5 CVE-2023-41750 Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before buil… Agent Mitigation only Fix from $1,6002023-08-31 HIGH 8.6 CVE-2020-23793 An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can res… Spice Server No fix yet Fix from $1,9502023-08-22 MEDIUM 6.1 CVE-2023-4434 Missing Authorization in GitHub repository hamza417/inure prior to build88. Inure Patch available Fix from $1,6002023-08-20 MEDIUM 6.1 CVE-2023-39507 Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a malicious intent to lead the… Rikunabi Next 11.5.0+ Fix from $1,6002023-08-16 MEDIUM 5.3 CVE-2023-40027 Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as `undefined`, the `adminMeta` … Keystone 5.5.1+ Fix from $1,6002023-08-15 HIGH 8.1 CVE-2023-39438 A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing spec… Contributor License Agreement Assistant 2.13.1+ Fix from $1,9502023-08-15 MEDIUM 5.5 CVE-2023-21288 In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local … Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21234 In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to… Android Mitigation only Fix from $1,6002023-08-14 MEDIUM 6.8 CVE-2023-21132 In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This co… Android Patch available Fix from $1,6002023-08-14 MEDIUM 6.8 CVE-2023-21133 In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This co… Android Patch available Fix from $1,6002023-08-14 MEDIUM 6.8 CVE-2023-21134 In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This co… Android Patch available Fix from $1,6002023-08-14 MEDIUM 6.8 CVE-2023-21140 In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This co… Android Patch available Fix from $1,6002023-08-14 MEDIUM 6.5 CVE-2023-4106 Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to … Mattermost 7.8.8 / 7.9.6+ Fix from $1,6002023-08-11 CRITICAL 9.8 CVE-2023-39966 1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead … 1panel No fix yet Fix from $2,3002023-08-10 MEDIUM 5.5 CVE-2023-40216 OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a… OpenBSD Patch available Fix from $1,6002023-08-10 HIGH 8.2 CVE-2023-37862 In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP … Wp 6070 Wvps Firmware 4.0.10+ Fix from $1,9502023-08-09 HIGH 7.5 CVE-2023-37860 In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of th… Wp 6070 Wvps Firmware 4.0.10+ Fix from $1,9502023-08-09 MEDIUM 6.5 CVE-2023-37492 SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BAS… Netweaver Application Server Abap Mitigation only Fix from $1,6002023-08-08 MEDIUM 5.5 CVE-2023-33906 In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privil… Android Mitigation only Fix from $1,6002023-08-07 MEDIUM 5.5 CVE-2023-33907 In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privi… Android Mitigation only Fix from $1,6002023-08-07 MEDIUM 5.5 CVE-2023-33908 In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges Android Mitigation only Fix from $1,6002023-08-07