Vulnerability index

Browse CVEs

6,925 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2023-1167 Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions sta… GitLab 15.8.5 / 15.9.4+ Fix from $1,6002023-04-05 CRITICAL 9.8 CVE-2023-1782 HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where … Nomad after 1.5.2 Fix from $2,3002023-04-05 CRITICAL 9.8 CVE-2022-4939 THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability c… Wcfm Membership 2.10.1+ Fix from $2,3002023-04-05 MEDIUM 6.5 CVE-2022-4940 The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due t… Wcfm Membership 2.10.11+ Fix from $1,6002023-04-05 HIGH 8.8 CVE-2022-4935 The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due … Wcfm Marketplace 3.4.12+ Fix from $1,9502023-04-05 HIGH 8.8 CVE-2022-4937 The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 … Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible 6.6.1+ Fix from $1,9502023-04-05 MEDIUM 6.5 CVE-2023-1865 The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when resetting plugin settings via… Yourchannel after 1.2.3 Fix from $1,6002023-04-05 MEDIUM 5.3 CVE-2023-1868 The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via … Yourchannel after 1.2.3 Fix from $1,6002023-04-05 HIGH 7.8 CVE-2023-26269 Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation b… James 3.7.4+ Fix from $1,9502023-04-03 MEDIUM 6.5 CVE-2023-28672 Jenkins OctoPerf Load Testing Plugin Plugin 4.5.1 and earlier does not perform a permission check in a connection test HTTP endpoint, allowing attack… Octoperf Load Testing after 4.5.1 Fix from $1,6002023-04-02 MEDIUM 5.4 CVE-2023-1774 When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an at… Mattermost Server 7.1.6+ Fix from $1,6002023-03-31 HIGH 8.1 CVE-2023-27701 MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html. Muyucms No fix yet Fix from $1,9502023-03-28 HIGH 7.5 CVE-2022-48350 The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality. Emui No fix yet Fix from $1,9502023-03-27 MEDIUM 6.5 CVE-2023-0335 The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delet… Wp Shamsi after 4.3.3 Fix from $1,6002023-03-27 MEDIUM 6.5 CVE-2023-0336 The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low… Ooohboi Steroids For Elementor 2.1.5+ Fix from $1,6002023-03-27 HIGH 7.8 CVE-2023-21015 In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This c… Android Mitigation only Fix from $1,9502023-03-24 HIGH 7.8 CVE-2023-21021 In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin user network settings due to … Android Patch available Fix from $1,9502023-03-24 MEDIUM 5.5 CVE-2023-21029 In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with Use… Android Patch available Fix from $1,6002023-03-24 HIGH 7.8 CVE-2023-21001 In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings of other users due to a miss… Android Patch available Fix from $1,9502023-03-24 HIGH 7.8 CVE-2023-21002 In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This c… Android Mitigation only Fix from $1,9502023-03-24 HIGH 7.8 CVE-2023-21003 In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This c… Android Patch available Fix from $1,9502023-03-24 HIGH 7.8 CVE-2023-21004 In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This c… Android Mitigation only Fix from $1,9502023-03-24 HIGH 7.8 CVE-2023-21005 In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This c… Android Patch available Fix from $1,9502023-03-24 MEDIUM 6.8 CVE-2023-20926 In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due to a missing permission check.… Android Patch available Fix from $1,6002023-03-24 HIGH 7.8 CVE-2023-20955 In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and uninstall applications for all use… Android Patch available Fix from $1,9502023-03-24 HIGH 7.8 CVE-2023-20959 In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local es… Android Mitigation only Fix from $1,9502023-03-24 MEDIUM 5.3 CVE-2023-1261 Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network. Wi Sun Software Development Kit after 1.5.0 Fix from $1,6002023-03-21 MEDIUM 5.3 CVE-2023-1262 Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through ne… Wireless Smart Ubiquitous Network Linux Border Router Firmware after 1.5.2 Fix from $1,6002023-03-21 HIGH 8.1 CVE-2022-45636 An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitra… Bofei Dbd\+ No fix yet Fix from $1,9502023-03-21 MEDIUM 6.5 CVE-2023-0890 The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes a… Shortcodes Ultimate 5.12.8+ Fix from $1,6002023-03-20