Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Desktop HIGH 7.8
CVE-2022-37326

Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by co…

Fix: 4.6.0+
Fix from $1,950 2023-04-27
Gen5w L Firmware HIGH 7.8
CVE-2023-26244

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, which is …

No fix yet
Fix from $1,950 2023-04-27
Gen5w L Firmware HIGH 7.8
CVE-2023-26245

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is u…

No fix yet
Fix from $1,950 2023-04-27
Gen5w L Firmware HIGH 7.8
CVE-2023-26246

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is u…

No fix yet
Fix from $1,950 2023-04-27
Central Server HIGH 8.8
CVE-2023-27107

Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows use…

Fix: 8.2+
Fix from $1,950 2023-04-26
Drupal MEDIUM 6.5
CVE-2023-31250

The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files t…

Fix: 7.96 / 9.4.14+
Fix from $1,600 2023-04-26
Drupal MEDIUM 5.4
CVE-2022-25274

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, r…

Fix: 9.3.12+
Fix from $1,600 2023-04-26
Fusion HIGH 7.8
CVE-2023-20871

VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate …

Fix: 13.0.2+
Fix from $1,950 2023-04-25
Eos MEDIUM 6.5
CVE-2023-24512

On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to updat…

Fix: 4.26.10m / 4.27.9m+
Fix from $1,600 2023-04-25
Odoo HIGH 7.5
CVE-2021-23203

Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to do…

Patch available
Fix from $1,950 2023-04-25
Workspace HIGH 7.8
CVE-2023-2257

Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker wit…

Fix: 2023.1.1.4+
Fix from $1,950 2023-04-24
Apsal MEDIUM 5.5
CVE-2023-26097

An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify the application behaviour may not be blocked.

No fix yet
Fix from $1,600 2023-04-24
Android HIGH 7.8
CVE-2023-20950

In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendingIntent. …

Patch available
Fix from $1,950 2023-04-19
Struxureware Data Center Expert HIGH 8.8
CVE-2023-25547

A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using …

Fix: after 7.9.2
Fix from $1,950 2023-04-18
Struxureware Data Center Expert MEDIUM 6.5
CVE-2023-25548

A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly se…

Fix: after 7.9.2
Fix from $1,600 2023-04-18
Iotdb Web Workbench CRITICAL 9.8
CVE-2023-30771

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd…

Mitigation only
Fix from $2,300 2023-04-17
Lilypond HIGH 8.6
CVE-2020-17354

LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangero…

Fix: 2.24.0+
Fix from $1,950 2023-04-15
Unified Threat Management HIGH 7.5
CVE-2023-22620

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an inva…

Fix: 12.2.5.1+
Fix from $1,950 2023-04-12
Windows 10 1809 MEDIUM 6.8
CVE-2023-28270

Windows Lock Screen Security Feature Bypass Vulnerability

Fix: 10.0.17763.4252 / 10.0.19042.2846+
Fix from $1,600 2023-04-11
Windows 10 1507 MEDIUM 6.8
CVE-2023-28249

Windows Boot Manager Security Feature Bypass Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,600 2023-04-11
Pe8108 Firmware MEDIUM 5.3
CVE-2023-25415

Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.

No fix yet
Fix from $1,600 2023-04-11
Forticlient HIGH 7.8
CVE-2022-40682

A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to exec…

Fix: 7.0.8+
Fix from $1,950 2023-04-11
Pentaho Business Analytics HIGH 8.1
CVE-2022-43770

Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in …

Fix: 8.3.0.27 / 9.2.0.4+
Fix from $1,950 2023-04-11
GitLab MEDIUM 5.3
CVE-2023-0319

An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all ve…

Fix: 15.8.5 / 15.9.4+
Fix from $1,600 2023-04-05
Glpi HIGH 8.8
CVE-2023-28634

GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technic…

Fix: 9.5.13 / 10.0.7+
Fix from $1,950 2023-04-05
Vantara Pentaho Business Analytics Server HIGH 8.8
CVE-2022-43940

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization chec…

Fix: 9.3.0.2+
Fix from $1,950 2023-04-03
Remote Desktop Manager MEDIUM 6.5
CVE-2023-1202

Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows us…

Fix: 2023.1.10+
Fix from $1,600 2023-04-02
Devolutions Server MEDIUM 6.5
CVE-2023-1603

Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restri…

Fix: 2023.1.3.0+
Fix from $1,600 2023-04-02
Cl4nx Plus Firmware CRITICAL 9.8
CVE-2023-23594

An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unaut…

Fix: 1.13.3-u724_r2+
Fix from $2,300 2023-03-31
Centrestack CRITICAL 9.8
CVE-2023-26829

An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new …

Fix: 13.5.9808+
Fix from $2,300 2023-03-31