Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Cax80 Firmware HIGH 8.8
CVE-2022-27642

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers.…

Fix: 1.0.1.78 / 1.0.4.126+
Fix from $1,950 2023-03-29
Infrasuite Device Master HIGH 8.8
CVE-2023-1144

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the…

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Infrasuite Device Master HIGH 7.5
CVE-2023-1136

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to …

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Iot Wall HIGH 8.1
CVE-2023-25017

RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote attacker with general user privilege is allowed to perform …

Mitigation only
Fix from $1,950 2023-03-27
Android HIGH 7.8
CVE-2023-21034

In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local …

Patch available
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-21035

In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same pac…

Patch available
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-20975

In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due to a permis…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-20971

In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic…

Mitigation only
Fix from $1,950 2023-03-24
Stationguard CRITICAL 9.8
CVE-2023-28611

Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access res…

Fix: after 2.20
Fix from $2,300 2023-03-23
Userlock HIGH 7.2
CVE-2023-23192

IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.

No fix yet
Fix from $1,950 2023-03-23
Clearpass Policy Manager HIGH 8.8
CVE-2023-25594

A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions tha…

Fix: after 6.10.8
Fix from $1,950 2023-03-22
Security Key Lifecycle Manager HIGH 8.8
CVE-2023-25924

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not…

Patch available
Fix from $1,950 2023-03-22
Security Key Lifecycle Manager HIGH 7.5
CVE-2023-25923

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of…

Patch available
Fix from $1,950 2023-03-21
Galaxy HIGH 7.5
CVE-2023-27578

Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an…

Fix: 22.01+
Fix from $1,950 2023-03-20
Profilegrid HIGH 8.8
CVE-2023-0940

The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. Th…

Fix: 5.3.1+
Fix from $1,950 2023-03-20
Cilium HIGH 7.3
CVE-2023-27594

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, under speci…

Fix: 1.11.15 / 1.12.8+
Fix from $1,950 2023-03-17
Kubevirt HIGH 8.2
CVE-2023-26484

KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has taken over a Kubernetes node wh…

Fix: after 0.59.0
Fix from $1,950 2023-03-15
Itop HIGH 7.5
CVE-2022-39214EPSS 26%

Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able …

Fix: 2.7.8 / 3.0.2-1+
Fix from $1,950 2023-03-14
Vault HIGH 8.1
CVE-2023-24999

HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the s…

Fix: 1.10.11 / 1.11.8+
Fix from $1,950 2023-03-11
Jenkins HIGH 7.0
CVE-2023-27899

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly…

Fix: 2.375.4 / 2.394+
Fix from $1,950 2023-03-10
Dynamic Application Security Testing Analyzer MEDIUM 6.5
CVE-2022-4315

An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with …

Fix: 3.0.55+
Fix from $1,600 2023-03-08
Zephyr Enterprise HIGH 8.1
CVE-2023-22891

There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset …

Fix: after 7.15
Fix from $1,950 2023-03-08
Xcat HIGH 8.8
CVE-2023-27486

xCAT is a toolkit for deployment and administration of computer clusters. In versions prior to 2.16.5 if zones are configured as a mechanism to secur…

Fix: 2.16.5+
Fix from $1,950 2023-03-08
Kylin Os HIGH 7.8
CVE-2023-1164

A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is some unknown functionality o…

Fix: 1.3.11-23 / 1.30.10-5.p23+
Fix from $1,950 2023-03-03
Xwiki MEDIUM 5.4
CVE-2023-26056

XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, pro…

Fix: 13.10.10 / 14.4.5+
Fix from $1,600 2023-03-02
Devolutions Server MEDIUM 6.5
CVE-2023-0952

Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without …

Fix: after 2022.3.12
Fix from $1,600 2023-03-01
Core MEDIUM 6.5
CVE-2023-25575

API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the…

Fix: 2.7.10 / 3.0.12+
Fix from $1,600 2023-02-28
macOS MEDIUM 5.5
CVE-2023-23510

A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access a user’s Safari h…

Fix: 13.2+
Fix from $1,600 2023-02-27
macOS MEDIUM 5.5
CVE-2023-23506

A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access user-sensitive da…

Fix: 13.2+
Fix from $1,600 2023-02-27
macOS MEDIUM 5.5
CVE-2022-46704

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, macOS Big Sur 11.7.2, macOS Monterey 12.6.2. A…

Fix: 11.7.2 / 12.6.2+
Fix from $1,600 2023-02-27