Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Wps Hide Login HIGH 7.5
CVE-2020-36710

The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page ma…

Fix: after 1.5.4.2
Fix from $1,950 2023-06-07
Experience Commerce HIGH 7.5
CVE-2023-33651

An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release…

Fix: after 10.3
Fix from $1,950 2023-06-06
Synapse MEDIUM 5.4
CVE-2023-32683

Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_ur…

Fix: 1.85.0+
Fix from $1,600 2023-06-06
Foundry MEDIUM 6.5
CVE-2023-22833

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Found…

Fix: after 2.531.0
Fix from $1,600 2023-06-06
315 5g Iot Modem Firmware HIGH 7.8
CVE-2023-21670

Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.

Patch available
Fix from $1,950 2023-06-06
Aqt1000 Firmware HIGH 7.8
CVE-2022-40529

Memory corruption due to improper access control in kernel while processing a mapping request from root process.

Mitigation only
Fix from $1,950 2023-06-06
Advanced Cluster Management For Kubernetes HIGH 7.8
CVE-2023-3027

The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value…

Mitigation only
Fix from $1,950 2023-06-05
Amxgt 100 HIGH 8.1
CVE-2023-3066

Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including admi…

Fix: after 1.3.20
Fix from $1,950 2023-06-05
Firefox HIGH 8.8
CVE-2023-25729

Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them wi…

Fix: 102.8 / 110.0+
Fix from $1,950 2023-06-02
Firefox MEDIUM 6.5
CVE-2023-23604

A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have l…

Fix: 109.0+
Fix from $1,600 2023-06-02
Mobatime Web Application HIGH 8.8
CVE-2023-3033

Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Secur…

Fix: after 06.7.22
Fix from $1,950 2023-06-02
Fantsy CRITICAL 9.8
CVE-2023-28698

Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can exploit this vulnerability by …

Mitigation only
Fix from $2,300 2023-06-02
U Lock Firmware HIGH 8.8
CVE-2022-46307

SGUDA U-Lock central lock control service’s lock management function has incorrect authorization. A remote attacker with general privilege can exploi…

Mitigation only
Fix from $1,950 2023-06-02
U Lock Firmware HIGH 8.8
CVE-2022-46308

SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can e…

Mitigation only
Fix from $1,950 2023-06-02
Teamcity CRITICAL 9.8
CVE-2023-34218

In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible

Fix: 2023.05+
Fix from $2,300 2023-05-31
Insight HIGH 7.4
CVE-2023-28352

An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled arti…

No fix yet
Fix from $1,950 2023-05-31
Xxl Job HIGH 8.8
CVE-2023-33779

A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POS…

Mitigation only
Fix from $1,950 2023-05-26
Emui HIGH 7.5
CVE-2023-31226

The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vulnerability may affect confide…

No fix yet
Fix from $1,950 2023-05-26
Linux Kernel MEDIUM 6.8
CVE-2023-2002

A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This f…

Fix: 6.4+
Fix from $1,600 2023-05-26
Alist HIGH 7.5
CVE-2023-31726

AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.

No fix yet
Fix from $1,950 2023-05-23
Connect Iq HIGH 7.5
CVE-2023-23299

The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malic…

Fix: after 4.1.7
Fix from $1,950 2023-05-23
Connect Iq CRITICAL 9.1
CVE-2023-23304

The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.Sensor…

Fix: after 4.1.7
Fix from $2,300 2023-05-23
Q Sl2 Firmware HIGH 8.8
CVE-2023-25946

Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent attacker to analyze the product…

Fix: after 2.0.9
Fix from $1,950 2023-05-23
Tr 71w Firmware CRITICAL 9.8
CVE-2023-27388

Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login t…

Mitigation only
Fix from $2,300 2023-05-23
Kace Systems Deployment Appliance MEDIUM 6.5
CVE-2023-33254

There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a high…

No fix yet
Fix from $1,600 2023-05-21
Telegram MEDIUM 5.5
CVE-2023-26818

Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.

No fix yet
Fix from $1,600 2023-05-19
Zammad MEDIUM 6.5
CVE-2023-31597

An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user. At…

Fix: 5.4.1+
Fix from $1,600 2023-05-18
Cyber Infrastructure MEDIUM 5.5
CVE-2023-2782

Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build …

Fix: 5.3.1-38+
Fix from $1,600 2023-05-18
Android MEDIUM 6.7
CVE-2023-21116

In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logi…

Patch available
Fix from $1,600 2023-05-15
Android HIGH 7.8
CVE-2023-21117

In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receiver due to…

Patch available
Fix from $1,950 2023-05-15