Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Aws Cloud Development Kit HIGH 8.8
CVE-2023-35165

AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through …

Fix: 1.202.0 / 2.80.0+
Fix from $1,950 2023-06-23
Itunes HIGH 7.8
CVE-2023-32353

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to elevate privileges.

Fix: 12.12.9+
Fix from $1,950 2023-06-23
Terraform Enterprise HIGH 7.7
CVE-2023-3114

Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unautho…

Fix: 202306-1+
Fix from $1,950 2023-06-22
Topdesk HIGH 8.1
CVE-2023-34923

XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credentials to authenticate with the Id…

No fix yet
Fix from $1,950 2023-06-22
Wavrouter App HIGH 7.5
CVE-2023-29708EPSS 14%

An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload.

No fix yet
Fix from $1,950 2023-06-22
Z\/ip Gateway Sdk HIGH 8.8
CVE-2023-0971

A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S…

Fix: after 7.18.01
Fix from $1,950 2023-06-21
Xwiki HIGH 8.8
CVE-2023-35166EPSS 63%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content wi…

Fix: 14.10.5+
Fix from $1,950 2023-06-20
Emui HIGH 7.5
CVE-2023-34161

nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation of this vulnerability may cause features to perform a…

Mitigation only
Fix from $1,950 2023-06-19
Emui MEDIUM 5.3
CVE-2022-48488

Vulnerability of bypassing the default desktop security controls.Successful exploitation of this vulnerability may cause unauthorized modifications t…

No fix yet
Fix from $1,600 2023-06-19
Emui MEDIUM 5.3
CVE-2022-48495

Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cause foreground app information…

No fix yet
Fix from $1,600 2023-06-19
Keepassxc MEDIUM 5.5
CVE-2023-35866

In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authenti…

Fix: after 2.7.5
Fix from $1,600 2023-06-19
Asika Airscale Firmware HIGH 7.8
CVE-2023-25185

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN…

Mitigation only
Fix from $1,950 2023-06-16
Commerce HIGH 7.5
CVE-2023-22248

Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerabili…

Mitigation only
Fix from $1,950 2023-06-15
Video Management System HIGH 7.7
CVE-2023-28175

Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted …

Fix: after 11.1.1
Fix from $1,950 2023-06-15
Security Guardium HIGH 7.8
CVE-2022-22307

IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force…

Patch available
Fix from $1,950 2023-06-15
Dragonfly Folio G3 2 In 1 Firmware HIGH 7.8
CVE-2022-31644

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation o…

Mitigation only
Fix from $1,950 2023-06-14
Dragonfly Folio G3 2 In 1 Firmware HIGH 7.8
CVE-2022-31646

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation o…

No fix yet
Fix from $1,950 2023-06-14
Discourse MEDIUM 5.3
CVE-2023-32061

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passe…

Fix: 3.0.4+
Fix from $1,600 2023-06-13
Cloudvision Portal HIGH 8.1
CVE-2023-24546

On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor …

Fix: after 2021.3
Fix from $1,950 2023-06-13
Sspanel Uim MEDIUM 5.3
CVE-2023-34965

SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.

No fix yet
Fix from $1,600 2023-06-13
Kafkaui Lite CRITICAL 9.8
CVE-2023-27716

An issue was discovered in freakchicken kafkaUI-lite 1.2.11 allows attackers on the same network to gain escalated privileges for the nodes running o…

Mitigation only
Fix from $2,300 2023-06-12
Mazda Firmware HIGH 7.5
CVE-2023-32219

A Mazda model (2015-2016) can be unlocked via an unspecified method.

No fix yet
Fix from $1,950 2023-06-12
Ncr\/camera Firmware CRITICAL 9.8
CVE-2023-32220

Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.

No fix yet
Fix from $2,300 2023-06-12
Sleep MEDIUM 5.5
CVE-2023-29761

An issue found in Sleep v.20230303 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference …

No fix yet
Fix from $1,600 2023-06-09
Crossx HIGH 7.8
CVE-2023-29766

An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause an escalation of Privileges via the database files.

No fix yet
Fix from $1,950 2023-06-09
Facemoji Emoji Keyboard HIGH 7.8
CVE-2023-29752

An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the…

No fix yet
Fix from $1,950 2023-06-09
Blue Light Filter MEDIUM 5.5
CVE-2023-29758

An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPr…

No fix yet
Fix from $1,600 2023-06-09
Flightaware MEDIUM 5.5
CVE-2023-29759

An issue found in FlightAware v.5.8.0 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the database files.

No fix yet
Fix from $1,600 2023-06-09
Cells HIGH 8.8
CVE-2023-32749EPSS 14%

Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when cre…

Fix: 3.0.12 / 4.1.3+
Fix from $1,950 2023-06-08
Jobsearch Wp Job Board MEDIUM 5.3
CVE-2021-4352

The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings funct…

Fix: after 1.8.1
Fix from $1,600 2023-06-07