Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.5 CVE-2023-33909 In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privil… Android Mitigation only Fix from $1,6002023-08-07 MEDIUM 5.5 CVE-2023-33910 In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privil… Android Mitigation only Fix from $1,6002023-08-07 MEDIUM 5.5 CVE-2023-33911 In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileg… Android Mitigation only Fix from $1,6002023-08-07 MEDIUM 5.5 CVE-2023-33912 In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privil… Android Mitigation only Fix from $1,6002023-08-07 HIGH 7.5 CVE-2023-38494 MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not ha… Metersphere 2.10.4+ Fix from $1,9502023-08-04 MEDIUM 5.9 CVE-2023-30950 The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint Foundry Campaigns 0.623.0+ Fix from $1,6002023-08-03 MEDIUM 6.5 CVE-2023-4124 Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1. Answer 1.1.1+ Fix from $1,6002023-08-03 MEDIUM 6.5 CVE-2023-0958 Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_instal… Backup Migration 1.1.4 / 1.2.8+ Fix from $1,6002023-07-28 HIGH 8.1 CVE-2023-38510 Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request is made using an API key, the … Tolgee 3.23.1+ Fix from $1,9502023-07-27 CRITICAL 9.8 CVE-2023-3956 The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capabil… Instawp Connect after 0.0.9.18 Fix from $2,3002023-07-27 HIGH 7.5 CVE-2023-3442 A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully… Servicenow Devops 1.38.1+ Fix from $1,9502023-07-26 MEDIUM 6.5 CVE-2022-43712 POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are not logged in. If an unauthori… Xperiencentral after 10.36.0 Fix from $1,6002023-07-26 MEDIUM 6.5 CVE-2023-37049 emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php. Emlog No fix yet Fix from $1,6002023-07-26 CRITICAL 9.8 CVE-2023-26301 Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege and/or Information Disclosure related to a lack of aut… Color Laserjet Pro 4201 4203 4ra87f Firmware 6.12.1.12-202306030312+ Fix from $2,3002023-07-21 MEDIUM 5.3 CVE-2023-3300 HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users … Nomad after 1.5.6 Fix from $1,6002023-07-20 HIGH 8.8 CVE-2023-33265 In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticat… Hazelcast 5.0.5 / 5.1.7+ Fix from $1,9502023-07-18 HIGH 8.8 CVE-2023-3713 The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check… Profilegrid after 5.5.1 Fix from $1,9502023-07-18 HIGH 8.8 CVE-2023-3714 The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler… Profilegrid 5.5.3+ Fix from $1,9502023-07-18 HIGH 7.5 CVE-2023-2268 Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users. Plane No fix yet Fix from $1,9502023-07-15 HIGH 7.8 CVE-2023-21257 In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission … Android Patch available Fix from $1,9502023-07-13 HIGH 7.8 CVE-2023-21247 In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due t… Android Patch available Fix from $1,9502023-07-13 HIGH 7.8 CVE-2023-21248 In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a m… Android Patch available Fix from $1,9502023-07-13 MEDIUM 5.4 CVE-2023-37963 A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to connect to an att… Benchmark Evaluator after 1.0.1 Fix from $1,6002023-07-12 HIGH 7.1 CVE-2023-37965 A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-… Elasticbox Ci after 5.0.1 Fix from $1,9502023-07-12 MEDIUM 6.5 CVE-2023-37944 A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specif… Datadog 5.4.2+ Fix from $1,6002023-07-12 HIGH 7.1 CVE-2023-37949 A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attac… Orka By Macstadium 1.34+ Fix from $1,9502023-07-12 MEDIUM 6.5 CVE-2023-37953 A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifie… Mabl after 0.0.46 Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-37956 A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Read permission to connect to a… Test Results Aggregator after 1.2.13 Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-37959 A missing permission check in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers with Overall/Read permission to connect to an att… Sumologic Publisher after 2.2.1 Fix from $1,6002023-07-12 MEDIUM 5.5 CVE-2023-33889 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android No fix yet Fix from $1,6002023-07-12