Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Kernelsu MEDIUM 5.7
CVE-2023-46139

KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelSU installed device is infecte…

Fix: 0.7.0+
Fix from $1,600 2023-10-31
Android HIGH 7.8
CVE-2023-21390

In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege …

Fix: 14.0+
Fix from $1,950 2023-10-30
Nats Server MEDIUM 6.5
CVE-2023-47090

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be …

Fix: 2.9.23 / 2.10.2+
Fix from $1,600 2023-10-30
Android MEDIUM 5.5
CVE-2023-21311

In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to local info…

Fix: 14.0+
Fix from $1,600 2023-10-30
Android HIGH 7.8
CVE-2023-40117

In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalati…

Patch available
Fix from $1,950 2023-10-27
Frrouting MEDIUM 5.9
CVE-2023-46753

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one wi…

Fix: after 9.0.1
Fix from $1,600 2023-10-26
Admin MEDIUM 5.3
CVE-2023-46754

The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values.

Fix: 1.1.2+
Fix from $1,600 2023-10-26
macOS MEDIUM 5.5
CVE-2023-41077

An app may be able to access protected user data. This issue is fixed in macOS Sonoma 14, macOS Ventura 13.6.1. The issue was addressed with improved…

Fix: 13.6.1+
Fix from $1,600 2023-10-25
Fides MEDIUM 6.5
CVE-2023-46125

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem…

Fix: 2.22.1+
Fix from $1,600 2023-10-25
Sa Token HIGH 8.8
CVE-2023-43961

An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authenticatio…

Fix: 1.36.0+
Fix from $1,950 2023-10-25
Clearpass Policy Manager MEDIUM 6.5
CVE-2023-43508

Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that…

Fix: 6.9.13 / 6.10.8+
Fix from $1,600 2023-10-25
Brizy HIGH 8.1
CVE-2020-36714

The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versio…

Fix: after 1.0.125
Fix from $1,950 2023-10-20
Fancy Product Designer HIGH 8.8
CVE-2021-4334

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the f…

Fix: 4.7.0+
Fix from $1,950 2023-10-20
Aria Operations For Logs CRITICAL 9.8
CVE-2023-34051EPSS 45%

VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operat…

Patch available
Fix from $2,300 2023-10-20
Jdk MEDIUM 5.3
CVE-2023-22067

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are aff…

Patch available
Fix from $1,600 2023-10-17
Exos CRITICAL 9.8
CVE-2023-43119

An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain esca…

Fix: 22.7 / 31.7.2+
Fix from $2,300 2023-10-16
Terminalfour MEDIUM 6.5
CVE-2023-29484

In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.

Patch available
Fix from $1,600 2023-10-16
Commerce HIGH 8.8
CVE-2023-38218

Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incor…

Mitigation only
Fix from $1,950 2023-10-13
Enterprise Wechat Privatization HIGH 7.5
CVE-2023-40829

There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.

Mitigation only
Fix from $1,950 2023-10-12
Vantage6 MEDIUM 5.4
CVE-2023-28635

vantage6 is privacy preserving federated learning infrastructure. Prior to version 4.0.0, malicious users may try to get access to resources they are…

Fix: 4.0.0+
Fix from $1,600 2023-10-11
Kernelsu CRITICAL 9.8
CVE-2023-5521

Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

Fix: 0.6.9+
Fix from $2,300 2023-10-11
Fortimail HIGH 8.8
CVE-2023-36556

An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allo…

Fix: after 7.0.5
Fix from $1,950 2023-10-10
N3m Firmware HIGH 7.5
CVE-2023-44860EPSS 20%

An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.

Mitigation only
Fix from $1,950 2023-10-06
Advanced Cluster Management For Kubernetes HIGH 7.5
CVE-2022-3248

A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the bo…

Mitigation only
Fix from $1,950 2023-10-05
Satellite HIGH 8.1
CVE-2023-1832

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of…

Fix: 4.3.7-3+
Fix from $1,950 2023-10-04
Uptimedc HIGH 8.8
CVE-2023-4997

Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other us…

Fix: 2.0.0.33940+
Fix from $1,950 2023-10-04
GitLab HIGH 7.5
CVE-2023-5106

An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0…

Fix: 16.2.8 / 16.3.5+
Fix from $1,950 2023-10-02
Mattermost MEDIUM 5.4
CVE-2023-5195

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not p…

Fix: 7.8.10 / 8.0.2+
Fix from $1,600 2023-09-29
macOS MEDIUM 5.5
CVE-2023-41078

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to bypass certain Pri…

Fix: 14.0+
Fix from $1,600 2023-09-27
Build Of Optaplanner HIGH 8.1
CVE-2023-4853

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti…

Fix: 1.10.2 / 2.13.8+
Fix from $1,950 2023-09-20