Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.8 CVE-2023-21254 In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a … Android Patch available Fix from $1,9502023-07-13 HIGH 7.8 CVE-2023-21256 In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. This could le… Android Patch available Fix from $1,9502023-07-13 HIGH 7.8 CVE-2023-21245 In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup … Android Patch available Fix from $1,9502023-07-13 MEDIUM 6.5 CVE-2023-37579 Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, … Pulsar 2.10.4+ Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-35908 Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommende… Airflow 2.6.3+ Fix from $1,6002023-07-12 HIGH 8.1 CVE-2023-30428 Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP… Pulsar 2.10.4+ Fix from $1,9502023-07-12 HIGH 8.8 CVE-2023-30429 Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Whe… Pulsar 2.10.4+ Fix from $1,9502023-07-12 CRITICAL 9.8 CVE-2023-36994 In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject … Travianz No fix yet Fix from $2,3002023-07-07 MEDIUM 5.4 CVE-2023-34197 Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation v… Manageengine Servicedesk Plus 14.2+ Fix from $1,6002023-07-07 MEDIUM 5.4 CVE-2023-36829 Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2, the Sentry API incorrectly r… Sentry 23.6.2+ Fix from $1,6002023-07-06 CRITICAL 9.8 CVE-2023-29381 An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the pa… Collaboration Mitigation only Fix from $2,3002023-07-06 HIGH 7.5 CVE-2022-48508 Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity. Emui No fix yet Fix from $1,9502023-07-06 CRITICAL 9.8 CVE-2022-46080 Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET. Nebula1200 Ac Firmware Mitigation only Fix from $2,3002023-07-06 MEDIUM 6.1 CVE-2023-29656 An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control … Threat Visualizer 6.0.15+ Fix from $1,6002023-07-06 HIGH 8.1 CVE-2023-35939 GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a f… Glpi 10.0.8+ Fix from $1,9502023-07-05 MEDIUM 6.5 CVE-2023-34107 GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights ch… Glpi 10.0.8+ Fix from $1,6002023-07-05 MEDIUM 6.5 CVE-2023-34106 GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights che… Glpi 10.0.8+ Fix from $1,6002023-07-05 CRITICAL 9.8 CVE-2021-46891 Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect servic… Emui No fix yet Fix from $2,3002023-07-05 CRITICAL 9.8 CVE-2021-46890 Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect servic… Emui No fix yet Fix from $2,3002023-07-05 CRITICAL 9.8 CVE-2023-26258EPSS 38% Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID … Udp after 9.0.6034 Fix from $2,3002023-07-03 CRITICAL 9.0 CVE-2023-31997 UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud… Unifi Os Mitigation only Fix from $2,3002023-07-01 MEDIUM 5.3 CVE-2023-37300 An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibi… Mediawiki after 1.39.3 Fix from $1,6002023-06-30 MEDIUM 5.4 CVE-2023-30955 A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Devel… Foundry Workspace Server 7.7.0+ Fix from $1,6002023-06-29 CRITICAL 9.8 CVE-2023-33190 Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper con… Sealos 4.2.1+ Fix from $2,3002023-06-29 HIGH 7.8 CVE-2023-21225 there is a possible way to bypass the protected confirmation screen due to Failure to lock display power. This could lead to local escalation of priv… Android Mitigation only Fix from $1,9502023-06-28 HIGH 7.8 CVE-2023-22593 IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redi… Robotic Process Automation after 23.0.3 Fix from $1,9502023-06-27 MEDIUM 5.3 CVE-2021-30205 Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse dep… Dzzoffice No fix yet Fix from $1,6002023-06-27 HIGH 7.8 CVE-2023-34146 An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca… Apex One 14.0.12518+ Fix from $1,9502023-06-26 HIGH 7.8 CVE-2023-34147 An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca… Apex One 14.0.12518+ Fix from $1,9502023-06-26 HIGH 7.8 CVE-2023-34148 An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca… Apex One 14.0.12518+ Fix from $1,9502023-06-26