Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Ftmg Esd20axx Firmware HIGH 7.5
CVE-2023-23445

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivi…

Fix: 2.0+
Fix from $1,950 2023-05-15
Ftmg Esd20axx Firmware HIGH 7.5
CVE-2023-23446

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivi…

Fix: 2.0+
Fix from $1,950 2023-05-15
Cloud Foundation HIGH 8.8
CVE-2023-20877

VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execu…

Fix: after 4.5
Fix from $1,950 2023-05-12
Aria Operations MEDIUM 6.7
CVE-2023-20880

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate p…

Fix: 8.12.0+
Fix from $1,600 2023-05-12
Secureanywhere MEDIUM 5.5
CVE-2023-29818

An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the def…

Fix: after 9.0.33.39
Fix from $1,600 2023-05-12
Secureanywhere MEDIUM 5.5
CVE-2023-29819

An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a craft…

Fix: after 9.0.33.39
Fix from $1,600 2023-05-12
Mattermost Server HIGH 8.8
CVE-2023-2515

Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to syst…

Fix: 7.1.8 / 7.7.4+
Fix from $1,950 2023-05-12
Rocket.chat MEDIUM 6.5
CVE-2023-28325

An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMes…

Fix: 6.0.0+
Fix from $1,600 2023-05-11
Endpoint Management Assistant MEDIUM 5.5
CVE-2022-45128

Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service vi…

Fix: 1.9.0.0+
Fix from $1,600 2023-05-10
Setup And Configuration Software MEDIUM 5.5
CVE-2022-43465

Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local ac…

Mitigation only
Fix from $1,600 2023-05-10
Endpoint Management Assistant Configuration Tool MEDIUM 5.5
CVE-2022-41610

Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated…

Fix: 1.0.4 / 2.4+
Fix from $1,600 2023-05-10
Windows 10 1507 MEDIUM 6.7
CVE-2023-24932EPSS 11%

Secure Boot Security Feature Bypass Vulnerability

Fix: 10.0.10240.19926 / 10.0.14393.5921+
Fix from $1,600 2023-05-09
Xwiki HIGH 8.8
CVE-2023-32069

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user …

Fix: 14.10.4+
Fix from $1,950 2023-05-09
Yershop HIGH 7.1
CVE-2020-23362

Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter.

No fix yet
Fix from $1,950 2023-05-09
Dhis 2 MEDIUM 6.5
CVE-2023-31138

DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to version…

Fix: 2.37.9.1 / 2.38.3.1+
Fix from $1,600 2023-05-09
Dhis 2 MEDIUM 6.5
CVE-2023-32060

DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to version…

Fix: 2.36.13 / 2.37.8+
Fix from $1,600 2023-05-09
Opensearch MEDIUM 5.9
CVE-2023-31141

OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10 and 2.7.0, there is an issue…

Fix: 1.3.10 / 2.7.0+
Fix from $1,600 2023-05-08
Ncr\/camera Firmware HIGH 7.5
CVE-2023-24505

Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.

No fix yet
Fix from $1,950 2023-05-08
macOS MEDIUM 5.5
CVE-2023-27951

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An archive may …

Fix: 11.7.5 / 12.6.4+
Fix from $1,600 2023-05-08
Safari MEDIUM 6.5
CVE-2023-27954

The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 …

Fix: 9.4 / 13.3+
Fix from $1,600 2023-05-08
macOS MEDIUM 5.5
CVE-2023-23538

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. An app may be able to modify prot…

Fix: 12.6.4 / 13.3+
Fix from $1,600 2023-05-08
Fluid HIGH 7.8
CVE-2023-30840

Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-intensive applications. Starting in version 0.7.0…

Fix: 0.8.6+
Fix from $1,950 2023-05-08
Web Stories MEDIUM 6.5
CVE-2023-1979

The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only ac…

Fix: 1.32.0+
Fix from $1,600 2023-05-08
Otrs HIGH 8.1
CVE-2023-2534

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and…

Fix: 8.0.32+
Fix from $1,950 2023-05-08
Big Iq Centralized Management MEDIUM 5.4
CVE-2023-29240

An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note:…

Fix: 8.3.0+
Fix from $1,600 2023-05-03
Evasys HIGH 8.1
CVE-2023-31435

Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire previews) in evasys before 8.2…

No fix yet
Fix from $1,950 2023-05-02
Cloud MEDIUM 6.5
CVE-2022-47874EPSS 21%

Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class '…

No fix yet
Fix from $1,600 2023-05-02
A921 Firmware MEDIUM 6.6
CVE-2023-30024

The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access…

No fix yet
Fix from $1,600 2023-04-28
Ms N5008 Uc Firmware CRITICAL 9.8
CVE-2023-30467

This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to i…

Fix: 71.9.0.18-r2 / 73.9.0.18-r2+
Fix from $2,300 2023-04-28
Ultimate Bulletin Board MEDIUM 5.3
CVE-2022-25091

Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be disclosed by unauthenticated use…

Fix: after 5.47a
Fix from $1,600 2023-04-27