Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2022-47553 Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive information for the organisati… Ekorrci Firmware Mitigation only Fix from $1,9502023-09-19 CRITICAL 9.8 CVE-2023-5009EPSS 8% An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It… GitLab 16.2.7 / 16.3.4+ Fix from $2,3002023-09-19 HIGH 7.1 CVE-2023-4814 A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the u… Data Loss Prevention Mitigation only Fix from $1,9502023-09-14 MEDIUM 5.3 CVE-2023-20190 A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker… Ios Xr 7.3.5 / 7.5.4+ Fix from $1,6002023-09-13 HIGH 7.5 CVE-2023-20191 A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unaut… Ios Xr 7.7.21 / 7.9.2+ Fix from $1,9502023-09-13 HIGH 8.8 CVE-2023-37881 Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0. Wing Ftp Server after 7.2.0 Fix from $1,9502023-09-12 CRITICAL 9.8 CVE-2023-40309 SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated … Commoncryptolib Mitigation only Fix from $2,3002023-09-12 HIGH 7.5 CVE-2023-30995 IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted… Aspera Faspex after 5.0.5 Fix from $1,9502023-09-08 MEDIUM 5.3 CVE-2023-37367 An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos… Exynos 9820 Firmware Mitigation only Fix from $1,6002023-09-08 CRITICAL 9.1 CVE-2023-20269 KEVEPSS 22% A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Softwar… Adaptive Security Appliance Software Mitigation only Fix from $2,3002023-09-06 MEDIUM 6.4 CVE-2023-38486 A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows an attacker to bypass securi… Arubaos 8.6.0.22 / 8.10.0.7+ Fix from $1,6002023-09-06 MEDIUM 5.4 CVE-2023-36387 An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test d… Superset after 2.1.0 Fix from $1,6002023-09-06 CRITICAL 9.8 CVE-2017-9453 BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass. Server Automation after 8.9.01 Fix from $2,3002023-09-05 MEDIUM 6.8 CVE-2023-34724 An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via the UART interface. La5570 Firmware No fix yet Fix from $1,6002023-08-28 MEDIUM 6.5 CVE-2023-4227 A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious … Iologik E4200 Firmware after 1.6 Fix from $1,6002023-08-24 HIGH 7.8 CVE-2023-3899 A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red… Subscription Manager 1.28.39 / 1.29.37+ Fix from $1,9502023-08-23 MEDIUM 5.3 CVE-2022-48538 In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() a… Cacti No fix yet Fix from $1,6002023-08-22 CRITICAL 9.8 CVE-2023-38035 KEVEPSS 100% A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentica… Mobileiron Sentry after 9.18.0 Fix from $2,3002023-08-21 MEDIUM 6.5 CVE-2023-40168 TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to version 1.8.0 allowed a maliciou… Turbowarp Desktop 1.8.0+ Fix from $1,6002023-08-17 HIGH 8.0 CVE-2023-40315 In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily esc… Horizon 32.0.2 / 2023.1.5+ Fix from $1,9502023-08-17 HIGH 8.8 CVE-2023-33237 TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate auth… Tn 5900 Firmware after 3.3 Fix from $1,9502023-08-17 CRITICAL 9.8 CVE-2023-32748 The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network… Mivoice Connect after 22.24.1500.0 Fix from $2,3002023-08-14 HIGH 7.5 CVE-2023-39384 Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to p… Emui No fix yet Fix from $1,9502023-08-13 MEDIUM 6.5 CVE-2023-4107 Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin'… Mattermost 7.8.8 / 7.9.6+ Fix from $1,6002023-08-11 MEDIUM 6.7 CVE-2023-28714 Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privil… Proset\/wireless Wifi 22.220.0+ Fix from $1,6002023-08-11 HIGH 7.8 CVE-2022-29871 Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated user to potentially enable escal… Converged Security Management Engine Firmware 4.0.48 / 11.8.94+ Fix from $1,9502023-08-11 MEDIUM 5.5 CVE-2023-30705 Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as G… Galaxy Store 4.5.56.6+ Fix from $1,6002023-08-10 CRITICAL 9.1 CVE-2023-33468 KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the de… Via Go2 Firmware 4.0.1.1326+ Fix from $2,3002023-08-09 MEDIUM 6.5 CVE-2023-24471 An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functional… Cmc 22.6.2+ Fix from $1,6002023-08-09 MEDIUM 6.5 CVE-2023-38209 Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Incorrect Authorization vulnerab… Commerce 2.4.4+ Fix from $1,6002023-08-09