Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2023-1299 HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fix… Nomad Mitigation only Fix from $1,9502023-03-14 HIGH 8.8 CVE-2023-27309 A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check … Ruggedcom Crossbow 5.2+ Fix from $1,9502023-03-14 HIGH 8.8 CVE-2023-27310 A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check … Ruggedcom Crossbow 5.2+ Fix from $1,9502023-03-14 CRITICAL 9.8 CVE-2022-48367 An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. Digital Experience Platform 1.1.9 / 1.3.17+ Fix from $2,3002023-03-12 MEDIUM 5.5 CVE-2022-47478 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47479 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android No fix yet Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47480 In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47481 In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47482 In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47483 In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47484 In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi… Android No fix yet Fix from $1,6002023-03-10 MEDIUM 6.7 CVE-2022-47461 In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. Android No fix yet Fix from $1,6002023-03-10 MEDIUM 6.7 CVE-2022-47462 In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47471 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47472 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47473 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47474 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47475 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47476 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android Mitigation only Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-47477 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android Mitigation only Fix from $1,6002023-03-10 CRITICAL 9.1 CVE-2023-26957 onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins. Onekeyadmin No fix yet Fix from $2,3002023-03-09 HIGH 7.5 CVE-2023-25573EPSS 52% metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/downl… Metersphere 1.20.19+ Fix from $1,9502023-03-09 MEDIUM 6.3 CVE-2020-36670 The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to m… Nex Forms after 7.7.1 Fix from $1,6002023-03-07 HIGH 8.8 CVE-2021-4331 The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free… The Plus Addons For Elementor after 4.1.9 Fix from $1,9502023-03-07 MEDIUM 5.4 CVE-2020-36667 The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes in versions up to, and inclu… Jetbackup after 1.4.1 Fix from $1,6002023-03-07 MEDIUM 5.3 CVE-2023-22858 An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs. Blogengine.net Mitigation only Fix from $1,6002023-03-06 MEDIUM 5.7 CVE-2023-26510 Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in … Ghost Mitigation only Fix from $1,6002023-03-05 CRITICAL 9.8 CVE-2023-1114 Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.10… E Belediye 1.0.0.100+ Fix from $2,3002023-03-01 MEDIUM 6.5 CVE-2023-27263 A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team… Mattermost after 7.1.4 Fix from $1,6002023-02-27 MEDIUM 6.5 CVE-2023-27264 A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks… Mattermost after 7.1.4 Fix from $1,6002023-02-27