Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Bosscms HIGH 7.8
CVE-2024-22938

Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function…

No fix yet
Fix from $1,950 2024-01-30
Mr2600 Firmware HIGH 7.5
CVE-2024-23629

An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access prote…

Mitigation only
Fix from $1,950 2024-01-26
Pocket Wifi 3 Firmware MEDIUM 6.5
CVE-2023-35836

An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. An attacker within RF range can obtain a cleartext copy of the network configuration…

Fix: after 3.009.03_20230504
Fix from $1,600 2024-01-23
Graphql MEDIUM 5.3
CVE-2023-44401

The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `…

Fix: 4.3.7 / 5.1.3+
Fix from $1,600 2024-01-23
Cloud MEDIUM 6.5
CVE-2024-23675

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST…

Fix: 9.0.8 / 9.1.3+
Fix from $1,600 2024-01-22
Emui HIGH 7.5
CVE-2023-52111

Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

No fix yet
Fix from $1,950 2024-01-16
GitLab MEDIUM 5.3
CVE-2023-4812

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all…

Fix: 16.5.5 / 16.6.4+
Fix from $1,600 2024-01-12
GitLab HIGH 8.8
CVE-2023-5356

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all…

Fix: 16.5.6 / 16.6.4+
Fix from $1,950 2024-01-12
macOS MEDIUM 5.5
CVE-2023-41994

A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the camera view fro…

Fix: 14.0+
Fix from $1,600 2024-01-10
S\/4hana Finance MEDIUM 6.5
CVE-2024-21736

SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A functio…

Mitigation only
Fix from $1,600 2024-01-09
Lt Replication Server HIGH 7.2
CVE-2024-21735

SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization …

Mitigation only
Fix from $1,950 2024-01-09
Zxcloud Irai MEDIUM 5.5
CVE-2023-41779

There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user…

Fix: 7.23.32+
Fix from $1,600 2024-01-03
Nexkey CRITICAL 9.8
CVE-2023-52077

Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens …

Fix: 12.23q4.5+
Fix from $2,300 2023-12-27
Wp Mail Log HIGH 7.6
CVE-2023-5644

The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view a…

Fix: 1.1.3+
Fix from $1,950 2023-12-26
Passwork HIGH 8.1
CVE-2023-49949

Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit codes.

Fix: 6.2.0+
Fix from $1,950 2023-12-26
Hertzbeat HIGH 7.5
CVE-2022-39337

Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v…

Fix: 1.2.1+
Fix from $1,950 2023-12-22
Xwiki MEDIUM 6.3
CVE-2023-50732

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script w…

Fix: 14.10.7 / 15.2+
Fix from $1,600 2023-12-21
Uc 500e Firmware MEDIUM 5.3
CVE-2023-50705

An attacker could create malicious requests to obtain sensitive information about the web server.

No fix yet
Fix from $1,600 2023-12-20
Superset MEDIUM 6.5
CVE-2023-49734

An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the…

Fix: 2.1.2 / 3.0.2+
Fix from $1,600 2023-12-19
Controller 7000 Firmware MEDIUM 6.8
CVE-2023-6355

Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local debug. T…

Fix: 8.70.231204a / 8.80.231204a+
Fix from $1,600 2023-12-18
Doris HIGH 8.2
CVE-2023-41314

The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Plea…

Fix: 2.0.3+
Fix from $1,950 2023-12-18
Api Manager HIGH 8.2
CVE-2023-6837

Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to ha…

Fix: 2.5.0.32 / 2.6.0.52+
Fix from $1,950 2023-12-15
I Access Client Solutions HIGH 8.8
CVE-2023-45185

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper author…

Fix: 1.1.9.4+
Fix from $1,950 2023-12-14
Silverpeas HIGH 8.1
CVE-2023-47320

Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function o…

Fix: 6.3.2+
Fix from $1,950 2023-12-13
Umbraco Cms MEDIUM 5.4
CVE-2023-49273

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low pr…

Fix: 8.18.10 / 10.8.1+
Fix from $1,600 2023-12-12
Rancher HIGH 8.8
CVE-2020-10676

In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace t…

Fix: 2.6.13 / 2.7.4+
Fix from $1,950 2023-12-12
Emarsys Sdk HIGH 7.1
CVE-2023-6542

Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages a…

Mitigation only
Fix from $1,950 2023-12-12
Cryptospike HIGH 8.8
CVE-2023-36646

Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute p…

No fix yet
Fix from $1,950 2023-12-12
A3002ru Firmware HIGH 8.8
CVE-2023-48859

TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end sec…

No fix yet
Fix from $1,950 2023-12-06
Emui HIGH 7.5
CVE-2023-49239

Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2023-12-06