Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2023-49240 Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality. Emui No fix yet Fix from $1,9502023-12-06 HIGH 7.5 CVE-2023-49246 Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. Emui Mitigation only Fix from $1,9502023-12-06 MEDIUM 6.8 CVE-2023-42575 Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid fl… Pass 4.3.00.17+ Fix from $1,6002023-12-05 HIGH 7.8 CVE-2023-33071 Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities. Qca6574 Firmware Patch available Fix from $1,9502023-12-05 MEDIUM 6.8 CVE-2023-24047 An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of w… Ac21000 G6 Firmware Mitigation only Fix from $1,6002023-12-04 CRITICAL 9.8 CVE-2023-24051 A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style… Ac21000 G6 Firmware Mitigation only Fix from $2,3002023-12-04 CRITICAL 9.8 CVE-2023-24052 An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as i… Ac21000 G6 Firmware Mitigation only Fix from $2,3002023-12-04 HIGH 7.5 CVE-2023-49947 Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication. Forgejo 1.20.5-1+ Fix from $1,9502023-12-03 MEDIUM 5.5 CVE-2023-42006 IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority … I Mitigation only Fix from $1,6002023-12-01 HIGH 7.5 CVE-2023-5995 An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all… GitLab 16.4.3 / 16.5.3+ Fix from $1,9502023-12-01 HIGH 7.5 CVE-2023-47827 Incorrect Authorization vulnerability in NicheAddons Events Addon for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This … Events Addon For Elementor 2.1.4+ Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-40610 Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database conn… Superset 2.1.2+ Fix from $1,9502023-11-27 HIGH 8.8 CVE-2023-48712 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. In affected versions there is a privilege escalation vulnerability through a … Warpgate after 0.8.1 Fix from $1,9502023-11-24 MEDIUM 6.8 CVE-2023-5553 During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as S… Axis Os 10.12.213 / 11.7.57+ Fix from $1,6002023-11-21 MEDIUM 5.4 CVE-2023-5799 The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles t… Wp Hotel Booking 2.0.8+ Fix from $1,6002023-11-20 MEDIUM 5.3 CVE-2023-48309 NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization a… Next Auth 4.24.5+ Fix from $1,6002023-11-20 MEDIUM 5.4 CVE-2023-5509 The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions. Mystickymenu 2.6.5+ Fix from $1,6002023-11-20 MEDIUM 5.3 CVE-2023-48218 The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.4, users were able to bypass … Protected Populate 1.3.4+ Fix from $1,6002023-11-20 MEDIUM 5.3 CVE-2023-3379 Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non… Compact Controller 100 Firmware 22+ Fix from $1,6002023-11-20 HIGH 7.2 CVE-2023-45626 An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code executio… Arubaos 8.6.0.23 / 8.10.0.9+ Fix from $1,9502023-11-14 HIGH 7.1 CVE-2022-40681 A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to caus… Forticlient after 7.0.7 Fix from $1,9502023-11-14 HIGH 8.0 CVE-2023-31403 SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any… Business One Mitigation only Fix from $1,9502023-11-14 HIGH 7.5 CVE-2023-4379 An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. … GitLab 16.2.8 / 16.3.5+ Fix from $1,9502023-11-09 HIGH 8.8 CVE-2023-46244 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a use… Xwiki 14.10.7 / 15.2+ Fix from $1,9502023-11-07 MEDIUM 5.3 CVE-2023-42553 Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email. Email 6.1.90.4+ Fix from $1,6002023-11-07 MEDIUM 5.3 CVE-2023-42541 Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id. Push Service 3.4.10+ Fix from $1,6002023-11-07 CRITICAL 9.9 CVE-2023-20048EPSS 16% A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to ex… Secure Firewall Management Center after 7.3.1.1 Fix from $2,3002023-11-01 HIGH 7.5 CVE-2023-46992 TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without au… A3300r Firmware No fix yet Fix from $1,9502023-10-31 CRITICAL 9.8 CVE-2023-22518 KEVEPSS 100% All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an… Confluence Data Center 7.19.16 / 8.3.4+ Fix from $2,3002023-10-31 HIGH 7.5 CVE-2023-45899 An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication … Superuser 2.4.2+ Fix from $1,9502023-10-31