Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Ekorrci Firmware HIGH 7.5
CVE-2022-47553

Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive information for the organisati…

Mitigation only
Fix from $1,950 2023-09-19
GitLab CRITICAL 9.8
CVE-2023-5009EPSS 8%

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It…

Fix: 16.2.7 / 16.3.4+
Fix from $2,300 2023-09-19
Data Loss Prevention HIGH 7.1
CVE-2023-4814

A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the u…

Mitigation only
Fix from $1,950 2023-09-14
Ios Xr MEDIUM 5.3
CVE-2023-20190

A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker…

Fix: 7.3.5 / 7.5.4+
Fix from $1,600 2023-09-13
Ios Xr HIGH 7.5
CVE-2023-20191

A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unaut…

Fix: 7.7.21 / 7.9.2+
Fix from $1,950 2023-09-13
Wing Ftp Server HIGH 8.8
CVE-2023-37881

Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.

Fix: after 7.2.0
Fix from $1,950 2023-09-12
Commoncryptolib CRITICAL 9.8
CVE-2023-40309

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …

Mitigation only
Fix from $2,300 2023-09-12
Aspera Faspex HIGH 7.5
CVE-2023-30995

IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted…

Fix: after 5.0.5
Fix from $1,950 2023-09-08
Exynos 9820 Firmware MEDIUM 5.3
CVE-2023-37367

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos…

Mitigation only
Fix from $1,600 2023-09-08
Adaptive Security Appliance Software CRITICAL 9.1
CVE-2023-20269 KEVEPSS 22%

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Softwar…

Mitigation only
Fix from $2,300 2023-09-06
Arubaos MEDIUM 6.4
CVE-2023-38486

A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows an attacker to bypass securi…

Fix: 8.6.0.22 / 8.10.0.7+
Fix from $1,600 2023-09-06
Superset MEDIUM 5.4
CVE-2023-36387

An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test d…

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Server Automation CRITICAL 9.8
CVE-2017-9453

BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.

Fix: after 8.9.01
Fix from $2,300 2023-09-05
La5570 Firmware MEDIUM 6.8
CVE-2023-34724

An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via the UART interface.

No fix yet
Fix from $1,600 2023-08-28
Iologik E4200 Firmware MEDIUM 6.5
CVE-2023-4227

A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious …

Fix: after 1.6
Fix from $1,600 2023-08-24
Subscription Manager HIGH 7.8
CVE-2023-3899

A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red…

Fix: 1.28.39 / 1.29.37+
Fix from $1,950 2023-08-23
Cacti MEDIUM 5.3
CVE-2022-48538

In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() a…

No fix yet
Fix from $1,600 2023-08-22
Mobileiron Sentry CRITICAL 9.8
CVE-2023-38035 KEVEPSS 100%

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentica…

Fix: after 9.18.0
Fix from $2,300 2023-08-21
Turbowarp Desktop MEDIUM 6.5
CVE-2023-40168

TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to version 1.8.0 allowed a maliciou…

Fix: 1.8.0+
Fix from $1,600 2023-08-17
Horizon HIGH 8.0
CVE-2023-40315

In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily esc…

Fix: 32.0.2 / 2023.1.5+
Fix from $1,950 2023-08-17
Tn 5900 Firmware HIGH 8.8
CVE-2023-33237

TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate auth…

Fix: after 3.3
Fix from $1,950 2023-08-17
Mivoice Connect CRITICAL 9.8
CVE-2023-32748

The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network…

Fix: after 22.24.1500.0
Fix from $2,300 2023-08-14
Emui HIGH 7.5
CVE-2023-39384

Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to p…

No fix yet
Fix from $1,950 2023-08-13
Mattermost MEDIUM 6.5
CVE-2023-4107

Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin'…

Fix: 7.8.8 / 7.9.6+
Fix from $1,600 2023-08-11
Proset\/wireless Wifi MEDIUM 6.7
CVE-2023-28714

Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privil…

Fix: 22.220.0+
Fix from $1,600 2023-08-11
Converged Security Management Engine Firmware HIGH 7.8
CVE-2022-29871

Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated user to potentially enable escal…

Fix: 4.0.48 / 11.8.94+
Fix from $1,950 2023-08-11
Galaxy Store MEDIUM 5.5
CVE-2023-30705

Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as G…

Fix: 4.5.56.6+
Fix from $1,600 2023-08-10
Via Go2 Firmware CRITICAL 9.1
CVE-2023-33468

KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the de…

Fix: 4.0.1.1326+
Fix from $2,300 2023-08-09
Cmc MEDIUM 6.5
CVE-2023-24471

An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functional…

Fix: 22.6.2+
Fix from $1,600 2023-08-09
Commerce MEDIUM 6.5
CVE-2023-38209

Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Incorrect Authorization vulnerab…

Fix: 2.4.4+
Fix from $1,600 2023-08-09