Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Node.js HIGH 7.5
CVE-2023-23918

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Perm…

Fix: 14.21.3 / 16.19.1+
Fix from $1,950 2023-02-23
A720r Firmware CRITICAL 9.8
CVE-2023-23064

TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.

No fix yet
Fix from $2,300 2023-02-17
Modular Open Smart Network CRITICAL 9.8
CVE-2021-32163

Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.

Fix: 0.23.0+
Fix from $2,300 2023-02-17
Workspace HIGH 7.8
CVE-2023-24485

Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix…

Fix: 2212+
Fix from $1,950 2023-02-16
Argo Cd HIGH 8.5
CVE-2023-23947

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2…

Fix: 2.3.17 / 2.4.23+
Fix from $1,950 2023-02-16
Containerd HIGH 7.8
CVE-2023-25173

containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not …

Fix: 1.5.18 / 1.6.18+
Fix from $1,950 2023-02-16
365 Apps HIGH 7.3
CVE-2023-21715 KEVEPSS 12%

Microsoft Publisher Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2023-02-14
Profile Builder MEDIUM 6.5
CVE-2023-0814

The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_met…

Fix: after 3.9.0
Fix from $1,600 2023-02-14
Evasa Provider Virtual Appliance MEDIUM 5.7
CVE-2022-34397

Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerabi…

Fix: 9.2.3.6 / 9.2.3.22+
Fix from $1,600 2023-02-13
Datahub HIGH 8.1
CVE-2023-25559

DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata…

Fix: 0.8.45+
Fix from $1,950 2023-02-11
Android MEDIUM 5.5
CVE-2023-21423

Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission…

Mitigation only
Fix from $1,600 2023-02-09
Android MEDIUM 5.5
CVE-2023-21422

Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server w…

Mitigation only
Fix from $1,600 2023-02-09
Cms HIGH 8.8
CVE-2022-45544

Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the t…

No fix yet
Fix from $1,950 2023-02-07
Command \| Intel Vpro Out Of Band HIGH 7.8
CVE-2023-23696

Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious user…

Fix: 4.4.0+
Fix from $1,950 2023-02-07
Ws Ftp Server HIGH 7.2
CVE-2023-24029

In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to ins…

Fix: 8.8+
Fix from $1,950 2023-02-03
Masacms CRITICAL 9.8
CVE-2022-47002EPSS 6%

A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.

Fix: 7.2.5 / 7.3.10+
Fix from $2,300 2023-02-01
Dompdf CRITICAL 9.8
CVE-2023-23924

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letter…

Patch available
Fix from $2,300 2023-02-01
Vdesk CRITICAL 9.8
CVE-2022-45172

An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endp…

Fix: 018+
Fix from $2,300 2023-01-31
Ecostruxure Geo Scada Expert 2019 HIGH 7.5
CVE-2023-22610

A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are se…

Patch available
Fix from $1,950 2023-01-31
Identityiq MEDIUM 6.5
CVE-2022-45435

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve…

Fix: 8.0+
Fix from $1,600 2023-01-31
Iotdb HIGH 8.8
CVE-2023-24829

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 bef…

Fix: 0.13.3+
Fix from $1,950 2023-01-31
Argo Cd HIGH 8.8
CVE-2023-22482

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6…

Fix: 2.3.14 / 2.4.20+
Fix from $1,950 2023-01-26
Glpi HIGH 7.5
CVE-2023-22500

GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to Incorrect Authorization. This v…

Fix: 10.0.6+
Fix from $1,950 2023-01-26
Edge Chromium MEDIUM 6.5
CVE-2023-21719

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Fix: 109.0.1518.70+
Fix from $1,600 2023-01-24
Ip Phone 7800 Firmware MEDIUM 6.5
CVE-2023-20018

A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker t…

Fix: 14.1+
Fix from $1,600 2023-01-20
Enterprise Server CRITICAL 9.8
CVE-2022-23739

An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests fr…

Fix: 3.3.16 / 3.4.11+
Fix from $2,300 2023-01-17
Betheme HIGH 8.1
CVE-2022-45353

Broken Access Control in Betheme theme <= 26.6.1 on WordPress.

Fix: after 26.6.1
Fix from $1,950 2023-01-14
Firefly Iii MEDIUM 6.5
CVE-2023-0298

Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.

Fix: 5.8.0+
Fix from $1,600 2023-01-14
Kubeoperator CRITICAL 9.8
CVE-2023-22480EPSS 67%

KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In Kube…

Fix: 3.16.4+
Fix from $2,300 2023-01-14
Lumada Asset Performance Management HIGH 7.1
CVE-2022-2155

A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on …

Fix: 6.4.0.1+
Fix from $1,950 2023-01-12