Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Emui HIGH 7.5
CVE-2023-49240

Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2023-12-06
Emui HIGH 7.5
CVE-2023-49246

Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

Mitigation only
Fix from $1,950 2023-12-06
Pass MEDIUM 6.8
CVE-2023-42575

Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid fl…

Fix: 4.3.00.17+
Fix from $1,600 2023-12-05
Qca6574 Firmware HIGH 7.8
CVE-2023-33071

Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.

Patch available
Fix from $1,950 2023-12-05
Ac21000 G6 Firmware MEDIUM 6.8
CVE-2023-24047

An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of w…

Mitigation only
Fix from $1,600 2023-12-04
Ac21000 G6 Firmware CRITICAL 9.8
CVE-2023-24051

A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style…

Mitigation only
Fix from $2,300 2023-12-04
Ac21000 G6 Firmware CRITICAL 9.8
CVE-2023-24052

An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as i…

Mitigation only
Fix from $2,300 2023-12-04
Forgejo HIGH 7.5
CVE-2023-49947

Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.

Fix: 1.20.5-1+
Fix from $1,950 2023-12-03
I MEDIUM 5.5
CVE-2023-42006

IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority …

Mitigation only
Fix from $1,600 2023-12-01
GitLab HIGH 7.5
CVE-2023-5995

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all…

Fix: 16.4.3 / 16.5.3+
Fix from $1,950 2023-12-01
Events Addon For Elementor HIGH 7.5
CVE-2023-47827

Incorrect Authorization vulnerability in NicheAddons Events Addon for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This …

Fix: 2.1.4+
Fix from $1,950 2023-11-30
Superset HIGH 8.8
CVE-2023-40610

Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database conn…

Fix: 2.1.2+
Fix from $1,950 2023-11-27
Warpgate HIGH 8.8
CVE-2023-48712

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. In affected versions there is a privilege escalation vulnerability through a …

Fix: after 0.8.1
Fix from $1,950 2023-11-24
Axis Os MEDIUM 6.8
CVE-2023-5553

During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as S…

Fix: 10.12.213 / 11.7.57+
Fix from $1,600 2023-11-21
Wp Hotel Booking MEDIUM 5.4
CVE-2023-5799

The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles t…

Fix: 2.0.8+
Fix from $1,600 2023-11-20
Next Auth MEDIUM 5.3
CVE-2023-48309

NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization a…

Fix: 4.24.5+
Fix from $1,600 2023-11-20
Mystickymenu MEDIUM 5.4
CVE-2023-5509

The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions.

Fix: 2.6.5+
Fix from $1,600 2023-11-20
Protected Populate MEDIUM 5.3
CVE-2023-48218

The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.4, users were able to bypass …

Fix: 1.3.4+
Fix from $1,600 2023-11-20
Compact Controller 100 Firmware MEDIUM 5.3
CVE-2023-3379

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non…

Fix: 22+
Fix from $1,600 2023-11-20
Arubaos HIGH 7.2
CVE-2023-45626

An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code executio…

Fix: 8.6.0.23 / 8.10.0.9+
Fix from $1,950 2023-11-14
Forticlient HIGH 7.1
CVE-2022-40681

A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to caus…

Fix: after 7.0.7
Fix from $1,950 2023-11-14
Business One HIGH 8.0
CVE-2023-31403

SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any…

Mitigation only
Fix from $1,950 2023-11-14
GitLab HIGH 7.5
CVE-2023-4379

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. …

Fix: 16.2.8 / 16.3.5+
Fix from $1,950 2023-11-09
Xwiki HIGH 8.8
CVE-2023-46244

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a use…

Fix: 14.10.7 / 15.2+
Fix from $1,950 2023-11-07
Email MEDIUM 5.3
CVE-2023-42553

Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.

Fix: 6.1.90.4+
Fix from $1,600 2023-11-07
Push Service MEDIUM 5.3
CVE-2023-42541

Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.

Fix: 3.4.10+
Fix from $1,600 2023-11-07
Secure Firewall Management Center CRITICAL 9.9
CVE-2023-20048EPSS 16%

A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to ex…

Fix: after 7.3.1.1
Fix from $2,300 2023-11-01
A3300r Firmware HIGH 7.5
CVE-2023-46992

TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without au…

No fix yet
Fix from $1,950 2023-10-31
Confluence Data Center CRITICAL 9.8
CVE-2023-22518 KEVEPSS 100%

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an…

Fix: 7.19.16 / 8.3.4+
Fix from $2,300 2023-10-31
Superuser HIGH 7.5
CVE-2023-45899

An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication …

Fix: 2.4.2+
Fix from $1,950 2023-10-31