Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Android HIGH 7.8
CVE-2023-21254

In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a …

Patch available
Fix from $1,950 2023-07-13
Android HIGH 7.8
CVE-2023-21256

In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. This could le…

Patch available
Fix from $1,950 2023-07-13
Android HIGH 7.8
CVE-2023-21245

In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup …

Patch available
Fix from $1,950 2023-07-13
Pulsar MEDIUM 6.5
CVE-2023-37579

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, …

Fix: 2.10.4+
Fix from $1,600 2023-07-12
Airflow MEDIUM 6.5
CVE-2023-35908

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommende…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Pulsar HIGH 8.1
CVE-2023-30428

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP…

Fix: 2.10.4+
Fix from $1,950 2023-07-12
Pulsar HIGH 8.8
CVE-2023-30429

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Whe…

Fix: 2.10.4+
Fix from $1,950 2023-07-12
Travianz CRITICAL 9.8
CVE-2023-36994

In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject …

No fix yet
Fix from $2,300 2023-07-07
Manageengine Servicedesk Plus MEDIUM 5.4
CVE-2023-34197

Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation v…

Fix: 14.2+
Fix from $1,600 2023-07-07
Sentry MEDIUM 5.4
CVE-2023-36829

Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2, the Sentry API incorrectly r…

Fix: 23.6.2+
Fix from $1,600 2023-07-06
Collaboration CRITICAL 9.8
CVE-2023-29381

An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the pa…

Mitigation only
Fix from $2,300 2023-07-06
Emui HIGH 7.5
CVE-2022-48508

Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.

No fix yet
Fix from $1,950 2023-07-06
Nebula1200 Ac Firmware CRITICAL 9.8
CVE-2022-46080

Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.

Mitigation only
Fix from $2,300 2023-07-06
Threat Visualizer MEDIUM 6.1
CVE-2023-29656

An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control …

Fix: 6.0.15+
Fix from $1,600 2023-07-06
Glpi HIGH 8.1
CVE-2023-35939

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a f…

Fix: 10.0.8+
Fix from $1,950 2023-07-05
Glpi MEDIUM 6.5
CVE-2023-34107

GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights ch…

Fix: 10.0.8+
Fix from $1,600 2023-07-05
Glpi MEDIUM 6.5
CVE-2023-34106

GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights che…

Fix: 10.0.8+
Fix from $1,600 2023-07-05
Emui CRITICAL 9.8
CVE-2021-46891

Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect servic…

No fix yet
Fix from $2,300 2023-07-05
Emui CRITICAL 9.8
CVE-2021-46890

Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect servic…

No fix yet
Fix from $2,300 2023-07-05
Udp CRITICAL 9.8
CVE-2023-26258EPSS 38%

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID …

Fix: after 9.0.6034
Fix from $2,300 2023-07-03
Unifi Os CRITICAL 9.0
CVE-2023-31997

UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud…

Mitigation only
Fix from $2,300 2023-07-01
Mediawiki MEDIUM 5.3
CVE-2023-37300

An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibi…

Fix: after 1.39.3
Fix from $1,600 2023-06-30
Foundry Workspace Server MEDIUM 5.4
CVE-2023-30955

A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Devel…

Fix: 7.7.0+
Fix from $1,600 2023-06-29
Sealos CRITICAL 9.8
CVE-2023-33190

Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper con…

Fix: 4.2.1+
Fix from $2,300 2023-06-29
Android HIGH 7.8
CVE-2023-21225

there is a possible way to bypass the protected confirmation screen due to Failure to lock display power. This could lead to local escalation of priv…

Mitigation only
Fix from $1,950 2023-06-28
Robotic Process Automation HIGH 7.8
CVE-2023-22593

IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redi…

Fix: after 23.0.3
Fix from $1,950 2023-06-27
Dzzoffice MEDIUM 5.3
CVE-2021-30205

Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse dep…

No fix yet
Fix from $1,600 2023-06-27
Apex One HIGH 7.8
CVE-2023-34146

An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca…

Fix: 14.0.12518+
Fix from $1,950 2023-06-26
Apex One HIGH 7.8
CVE-2023-34147

An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca…

Fix: 14.0.12518+
Fix from $1,950 2023-06-26
Apex One HIGH 7.8
CVE-2023-34148

An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca…

Fix: 14.0.12518+
Fix from $1,950 2023-06-26