Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 8.8 CVE-2023-37491 The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL… Message Server Mitigation only Fix from $1,9502023-08-08 MEDIUM 6.5 CVE-2023-37492 SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BAS… Netweaver Application Server Abap Mitigation only Fix from $1,6002023-08-08 MEDIUM 5.9 CVE-2023-39363 Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In versions 0.2.15, 0.2.16 and 0.3.0, named re-entrancy locks are… Vyper Patch available Fix from $1,6002023-08-07 HIGH 7.5 CVE-2023-32783 The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accoun… Manageengine Adaudit Plus No fix yet Fix from $1,9502023-08-07 MEDIUM 5.5 CVE-2023-4194 A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized acc… Linux Kernel after 6.4 Fix from $1,6002023-08-07 MEDIUM 6.5 CVE-2023-20800 In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System execution privile… Yocto Mitigation only Fix from $1,6002023-08-07 MEDIUM 6.5 CVE-2023-28468 An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI… Kernel after 5.5 Fix from $1,6002023-08-03 MEDIUM 5.3 CVE-2023-38958 An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platfo… Bioaccess Ivs Mitigation only Fix from $1,6002023-08-03 MEDIUM 6.5 CVE-2023-23476 IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation… Robotic Process Automation 23.0.0+ Fix from $1,6002023-08-02 CRITICAL 9.8 CVE-2023-36089 Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_… Dir 645 Firmware Mitigation only Fix from $2,3002023-07-31 CRITICAL 9.8 CVE-2023-36090 Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerabi… Dir 885l Firmware Mitigation only Fix from $2,3002023-07-31 CRITICAL 9.8 CVE-2023-36091 Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in c… Dir 895l Firmware Mitigation only Fix from $2,3002023-07-31 CRITICAL 9.8 CVE-2023-36092 Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This v… Dir 859 Firmware Mitigation only Fix from $2,3002023-07-31 HIGH 8.8 CVE-2023-38488 Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that… Kirby 3.5.8.3 / 3.6.6.3+ Fix from $1,9502023-07-27 MEDIUM 5.5 CVE-2023-35983 This issue was addressed with improved data protection. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. An ap… macOS 11.7.9 / 12.6.8+ Fix from $1,6002023-07-27 MEDIUM 6.5 CVE-2023-39154 Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permiss… Qualys Web App Scanning Connector after 2.0.10 Fix from $1,6002023-07-26 MEDIUM 6.5 CVE-2023-38503 Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permissi… Directus 10.5.0+ Fix from $1,6002023-07-25 HIGH 7.5 CVE-2023-38493 Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spring controllers via `TomcatSe… Armeria 1.24.3+ Fix from $1,9502023-07-25 MEDIUM 6.5 CVE-2023-36826 Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can do… Sentry 23.5.2+ Fix from $1,6002023-07-25 HIGH 7.5 CVE-2023-36339 An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET request. Webboss.io Cms 3.7.0.1+ Fix from $1,9502023-07-21 MEDIUM 6.5 CVE-2023-3484 An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, a… GitLab 15.11.11 / 16.0.7+ Fix from $1,6002023-07-21 MEDIUM 6.5 CVE-2023-32261 A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Overall/Re… Dimensions Cm 0.9.3.1+ Fix from $1,6002023-07-19 MEDIUM 5.3 CVE-2023-34035 Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration i… Spring Security 5.8.5 / 6.0.5+ Fix from $1,6002023-07-18 HIGH 8.8 CVE-2022-26563 An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization. Monit 5.31.0+ Fix from $1,9502023-07-18 HIGH 7.2 CVE-2023-3459 The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… Import Export Wordpress Users after 2.4.1 Fix from $1,9502023-07-18 MEDIUM 5.4 CVE-2023-3586 Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared … Mattermost Server 7.8.7 / 7.9.5+ Fix from $1,6002023-07-17 HIGH 7.5 CVE-2023-3590 Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments. Mattermost Server 7.10.3+ Fix from $1,9502023-07-17 HIGH 8.8 CVE-2023-2759 A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other u… Core Firmware 2023.2+ Fix from $1,9502023-07-17 CRITICAL 9.8 CVE-2023-31704 Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to… Online Computer And Laptop Store No fix yet Fix from $2,3002023-07-13 MEDIUM 6.5 CVE-2023-3444 An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6… GitLab 15.11.10 / 16.0.6+ Fix from $1,6002023-07-13