Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.7
CVE-2023-46139
KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelSU installed device is infecte…
Kernelsu
0.7.0+
HIGH 7.8
CVE-2023-21390
In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege …
Android
14.0+
MEDIUM 6.5
CVE-2023-47090
NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be …
Nats Server
2.9.23 / 2.10.2+
MEDIUM 5.5
CVE-2023-21311
In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to local info…
Android
14.0+
HIGH 7.8
CVE-2023-40117
In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalati…
Android
Patch available
MEDIUM 5.9
CVE-2023-46753
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one wi…
Frrouting
after 9.0.1
MEDIUM 5.3
CVE-2023-46754
The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values.
Admin
1.1.2+
MEDIUM 5.5
CVE-2023-41077
An app may be able to access protected user data. This issue is fixed in macOS Sonoma 14, macOS Ventura 13.6.1. The issue was addressed with improved…
macOS
13.6.1+
MEDIUM 6.5
CVE-2023-46125
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem…
Fides
2.22.1+
HIGH 8.8
CVE-2023-43961
An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authenticatio…
Sa Token
1.36.0+
MEDIUM 6.5
CVE-2023-43508
Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that…
Clearpass Policy Manager
6.9.13 / 6.10.8+
HIGH 8.1
CVE-2020-36714
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versio…
Brizy
after 1.0.125
HIGH 8.8
CVE-2021-4334
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the f…
Fancy Product Designer
4.7.0+
CRITICAL 9.8
CVE-2023-34051EPSS 45%
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operat…
Aria Operations For Logs
Patch available
MEDIUM 5.3
CVE-2023-22067
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are aff…
Jdk
Patch available
CRITICAL 9.8
CVE-2023-43119
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain esca…
Exos
22.7 / 31.7.2+
MEDIUM 6.5
CVE-2023-29484
In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.
Terminalfour
Patch available
HIGH 8.8
CVE-2023-38218
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incor…
Commerce
Mitigation only
HIGH 7.5
CVE-2023-40829
There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.
Enterprise Wechat Privatization
Mitigation only
MEDIUM 5.4
CVE-2023-28635
vantage6 is privacy preserving federated learning infrastructure. Prior to version 4.0.0, malicious users may try to get access to resources they are…
Vantage6
4.0.0+
CRITICAL 9.8
CVE-2023-5521
Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.
Kernelsu
0.6.9+
HIGH 8.8
CVE-2023-36556
An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allo…
Fortimail
after 7.0.5
HIGH 7.5
CVE-2023-44860EPSS 20%
An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.
N3m Firmware
Mitigation only
HIGH 7.5
CVE-2022-3248
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the bo…
Advanced Cluster Management For Kubernetes
Mitigation only
HIGH 8.1
CVE-2023-1832
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of…
Satellite
4.3.7-3+
HIGH 8.8
CVE-2023-4997
Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other us…
Uptimedc
2.0.0.33940+
HIGH 7.5
CVE-2023-5106
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0…
GitLab
16.2.8 / 16.3.5+
MEDIUM 5.4
CVE-2023-5195
Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not p…
Mattermost
7.8.10 / 8.0.2+
MEDIUM 5.5
CVE-2023-41078
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to bypass certain Pri…
macOS
14.0+
HIGH 8.1
CVE-2023-4853
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti…
Build Of Optaplanner
1.10.2 / 2.13.8+