Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.7 CVE-2023-46139 KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelSU installed device is infecte… Kernelsu 0.7.0+ Fix from $1,6002023-10-31 HIGH 7.8 CVE-2023-21390 In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege … Android 14.0+ Fix from $1,9502023-10-30 MEDIUM 6.5 CVE-2023-47090 NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be … Nats Server 2.9.23 / 2.10.2+ Fix from $1,6002023-10-30 MEDIUM 5.5 CVE-2023-21311 In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to local info… Android 14.0+ Fix from $1,6002023-10-30 HIGH 7.8 CVE-2023-40117 In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalati… Android Patch available Fix from $1,9502023-10-27 MEDIUM 5.9 CVE-2023-46753 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one wi… Frrouting after 9.0.1 Fix from $1,6002023-10-26 MEDIUM 5.3 CVE-2023-46754 The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values. Admin 1.1.2+ Fix from $1,6002023-10-26 MEDIUM 5.5 CVE-2023-41077 An app may be able to access protected user data. This issue is fixed in macOS Sonoma 14, macOS Ventura 13.6.1. The issue was addressed with improved… macOS 13.6.1+ Fix from $1,6002023-10-25 MEDIUM 6.5 CVE-2023-46125 Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem… Fides 2.22.1+ Fix from $1,6002023-10-25 HIGH 8.8 CVE-2023-43961 An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authenticatio… Sa Token 1.36.0+ Fix from $1,9502023-10-25 MEDIUM 6.5 CVE-2023-43508 Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that… Clearpass Policy Manager 6.9.13 / 6.10.8+ Fix from $1,6002023-10-25 HIGH 8.1 CVE-2020-36714 The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versio… Brizy after 1.0.125 Fix from $1,9502023-10-20 HIGH 8.8 CVE-2021-4334 The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the f… Fancy Product Designer 4.7.0+ Fix from $1,9502023-10-20 CRITICAL 9.8 CVE-2023-34051EPSS 45% VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operat… Aria Operations For Logs Patch available Fix from $2,3002023-10-20 MEDIUM 5.3 CVE-2023-22067 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are aff… Jdk Patch available Fix from $1,6002023-10-17 CRITICAL 9.8 CVE-2023-43119 An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain esca… Exos 22.7 / 31.7.2+ Fix from $2,3002023-10-16 MEDIUM 6.5 CVE-2023-29484 In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password. Terminalfour Patch available Fix from $1,6002023-10-16 HIGH 8.8 CVE-2023-38218 Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incor… Commerce Mitigation only Fix from $1,9502023-10-13 HIGH 7.5 CVE-2023-40829 There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000. Enterprise Wechat Privatization Mitigation only Fix from $1,9502023-10-12 MEDIUM 5.4 CVE-2023-28635 vantage6 is privacy preserving federated learning infrastructure. Prior to version 4.0.0, malicious users may try to get access to resources they are… Vantage6 4.0.0+ Fix from $1,6002023-10-11 CRITICAL 9.8 CVE-2023-5521 Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9. Kernelsu 0.6.9+ Fix from $2,3002023-10-11 HIGH 8.8 CVE-2023-36556 An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allo… Fortimail after 7.0.5 Fix from $1,9502023-10-10 HIGH 7.5 CVE-2023-44860EPSS 20% An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request. N3m Firmware Mitigation only Fix from $1,9502023-10-06 HIGH 7.5 CVE-2022-3248 A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the bo… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,9502023-10-05 HIGH 8.1 CVE-2023-1832 An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of… Satellite 4.3.7-3+ Fix from $1,9502023-10-04 HIGH 8.8 CVE-2023-4997 Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other us… Uptimedc 2.0.0.33940+ Fix from $1,9502023-10-04 HIGH 7.5 CVE-2023-5106 An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0… GitLab 16.2.8 / 16.3.5+ Fix from $1,9502023-10-02 MEDIUM 5.4 CVE-2023-5195 Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not p… Mattermost 7.8.10 / 8.0.2+ Fix from $1,6002023-09-29 MEDIUM 5.5 CVE-2023-41078 An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to bypass certain Pri… macOS 14.0+ Fix from $1,6002023-09-27 HIGH 8.1 CVE-2023-4853 A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti… Build Of Optaplanner 1.10.2 / 2.13.8+ Fix from $1,9502023-09-20