Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.1 CVE-2023-36815 Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sea… Sealos after 4.2.0 Fix from $1,9502023-07-03 MEDIUM 5.3 CVE-2021-4388 The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missin… Opal Estate after 1.6.11 Fix from $1,6002023-07-01 HIGH 7.5 CVE-2023-30586 A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is en… Node.js 20.3.1+ Fix from $1,9502023-07-01 HIGH 7.5 CVE-2023-36144EPSS 37% An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the dev… Sg 2404 Mr Firmware No fix yet Fix from $1,9502023-06-30 MEDIUM 5.3 CVE-2023-36607 The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information… Tbox Ms Cpu32 Firmware after 1.50.598 Fix from $1,6002023-06-29 MEDIUM 5.5 CVE-2023-21173 In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. … Android Mitigation only Fix from $1,6002023-06-28 MEDIUM 5.5 CVE-2023-21177 In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing per… Android Mitigation only Fix from $1,6002023-06-28 HIGH 7.8 CVE-2023-21185 In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalation of privilege from the gues… Android Mitigation only Fix from $1,9502023-06-28 HIGH 7.8 CVE-2023-21149 In registerGsmaServiceIntentReceiver of ShannonRcsService.java, there is a possible way to activate/deactivate RCS service due to a missing permissio… Android Mitigation only Fix from $1,9502023-06-28 MEDIUM 6.5 CVE-2023-36000 A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an a… Insider Threat Management Server 7.14.3+ Fix from $1,6002023-06-27 MEDIUM 6.5 CVE-2023-35164 DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing aut… Dataease 1.18.8+ Fix from $1,6002023-06-26 HIGH 8.1 CVE-2023-34463 DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized … Dataease 1.18.8+ Fix from $1,9502023-06-26 HIGH 8.8 CVE-2023-36348EPSS 6% POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter. Codekop No fix yet Fix from $1,9502023-06-23 MEDIUM 6.5 CVE-2023-23344 A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page. Bigfix Webui Insights Mitigation only Fix from $1,6002023-06-23 MEDIUM 6.5 CVE-2023-35093 Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions al… Masterstudy Lms after 3.0.8 Fix from $1,6002023-06-22 MEDIUM 5.3 CVE-2022-48491 Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead to ads and other windows to d… Emui Mitigation only Fix from $1,6002023-06-19 HIGH 8.1 CVE-2022-46850 Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin <= 0.1.3 versions. Easy Media Replace after 0.1.3 Fix from $1,9502023-06-19 MEDIUM 6.5 CVE-2023-2784 Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install… Mattermost after 7.9.3 Fix from $1,6002023-06-16 MEDIUM 6.5 CVE-2023-2787 Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message thre… Mattermost after 7.9.3 Fix from $1,6002023-06-16 MEDIUM 6.5 CVE-2023-2788 Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persi… Mattermost after 7.9.3 Fix from $1,6002023-06-16 MEDIUM 5.3 CVE-2023-34165 Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-pa… Harmonyos Mitigation only Fix from $1,6002023-06-16 MEDIUM 5.5 CVE-2023-21141 In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local … Android Patch available Fix from $1,6002023-06-15 HIGH 7.8 CVE-2023-21122 In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing per… Android Mitigation only Fix from $1,9502023-06-15 HIGH 7.8 CVE-2023-21123 In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing p… Android Mitigation only Fix from $1,9502023-06-15 MEDIUM 6.5 CVE-2023-35149 A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to con… Digital.ai App Management Publisher after 2.6 Fix from $1,6002023-06-14 HIGH 7.5 CVE-2023-3230 Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0. Fossbilling 0.5.0+ Fix from $1,9502023-06-14 MEDIUM 5.3 CVE-2023-2280 The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on th… Wp Directory Kit 1.2.3+ Fix from $1,6002023-06-09 MEDIUM 5.4 CVE-2023-2275 The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a mi… Woocommerce Multivendor Marketplace after 1.5.3 Fix from $1,6002023-06-09 MEDIUM 5.3 CVE-2023-1843 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability … Metform Elementor Contact Form Builder after 3.3.0 Fix from $1,6002023-06-09 CRITICAL 9.1 CVE-2023-0291 The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the … Quiz And Survey Master after 8.0.8 Fix from $2,3002023-06-09