Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Message Server HIGH 8.8
CVE-2023-37491

The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL…

Mitigation only
Fix from $1,950 2023-08-08
Netweaver Application Server Abap MEDIUM 6.5
CVE-2023-37492

SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BAS…

Mitigation only
Fix from $1,600 2023-08-08
Vyper MEDIUM 5.9
CVE-2023-39363

Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In versions 0.2.15, 0.2.16 and 0.3.0, named re-entrancy locks are…

Patch available
Fix from $1,600 2023-08-07
Manageengine Adaudit Plus HIGH 7.5
CVE-2023-32783

The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accoun…

No fix yet
Fix from $1,950 2023-08-07
Linux Kernel MEDIUM 5.5
CVE-2023-4194

A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized acc…

Fix: after 6.4
Fix from $1,600 2023-08-07
Yocto MEDIUM 6.5
CVE-2023-20800

In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System execution privile…

Mitigation only
Fix from $1,600 2023-08-07
Kernel MEDIUM 6.5
CVE-2023-28468

An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI…

Fix: after 5.5
Fix from $1,600 2023-08-03
Bioaccess Ivs MEDIUM 5.3
CVE-2023-38958

An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platfo…

Mitigation only
Fix from $1,600 2023-08-03
Robotic Process Automation MEDIUM 6.5
CVE-2023-23476

IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation…

Fix: 23.0.0+
Fix from $1,600 2023-08-02
Dir 645 Firmware CRITICAL 9.8
CVE-2023-36089

Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_…

Mitigation only
Fix from $2,300 2023-07-31
Dir 885l Firmware CRITICAL 9.8
CVE-2023-36090

Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerabi…

Mitigation only
Fix from $2,300 2023-07-31
Dir 895l Firmware CRITICAL 9.8
CVE-2023-36091

Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in c…

Mitigation only
Fix from $2,300 2023-07-31
Dir 859 Firmware CRITICAL 9.8
CVE-2023-36092

Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This v…

Mitigation only
Fix from $2,300 2023-07-31
Kirby HIGH 8.8
CVE-2023-38488

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that…

Fix: 3.5.8.3 / 3.6.6.3+
Fix from $1,950 2023-07-27
macOS MEDIUM 5.5
CVE-2023-35983

This issue was addressed with improved data protection. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. An ap…

Fix: 11.7.9 / 12.6.8+
Fix from $1,600 2023-07-27
Qualys Web App Scanning Connector MEDIUM 6.5
CVE-2023-39154

Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permiss…

Fix: after 2.0.10
Fix from $1,600 2023-07-26
Directus MEDIUM 6.5
CVE-2023-38503

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permissi…

Fix: 10.5.0+
Fix from $1,600 2023-07-25
Armeria HIGH 7.5
CVE-2023-38493

Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spring controllers via `TomcatSe…

Fix: 1.24.3+
Fix from $1,950 2023-07-25
Sentry MEDIUM 6.5
CVE-2023-36826

Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can do…

Fix: 23.5.2+
Fix from $1,600 2023-07-25
Webboss.io Cms HIGH 7.5
CVE-2023-36339

An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET request.

Fix: 3.7.0.1+
Fix from $1,950 2023-07-21
GitLab MEDIUM 6.5
CVE-2023-3484

An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, a…

Fix: 15.11.11 / 16.0.7+
Fix from $1,600 2023-07-21
Dimensions Cm MEDIUM 6.5
CVE-2023-32261

A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Overall/Re…

Fix: 0.9.3.1+
Fix from $1,600 2023-07-19
Spring Security MEDIUM 5.3
CVE-2023-34035

Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration i…

Fix: 5.8.5 / 6.0.5+
Fix from $1,600 2023-07-18
Monit HIGH 8.8
CVE-2022-26563

An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization.

Fix: 5.31.0+
Fix from $1,950 2023-07-18
Import Export Wordpress Users HIGH 7.2
CVE-2023-3459

The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o…

Fix: after 2.4.1
Fix from $1,950 2023-07-18
Mattermost Server MEDIUM 5.4
CVE-2023-3586

Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared …

Fix: 7.8.7 / 7.9.5+
Fix from $1,600 2023-07-17
Mattermost Server HIGH 7.5
CVE-2023-3590

Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.

Fix: 7.10.3+
Fix from $1,950 2023-07-17
Core Firmware HIGH 8.8
CVE-2023-2759

A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other u…

Fix: 2023.2+
Fix from $1,950 2023-07-17
Online Computer And Laptop Store CRITICAL 9.8
CVE-2023-31704

Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to…

No fix yet
Fix from $2,300 2023-07-13
GitLab MEDIUM 6.5
CVE-2023-3444

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6…

Fix: 15.11.10 / 16.0.6+
Fix from $1,600 2023-07-13