Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2020-36710 The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page ma… Wps Hide Login after 1.5.4.2 Fix from $1,9502023-06-07 HIGH 7.5 CVE-2023-33651 An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release… Experience Commerce after 10.3 Fix from $1,9502023-06-06 MEDIUM 5.4 CVE-2023-32683 Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_ur… Synapse 1.85.0+ Fix from $1,6002023-06-06 MEDIUM 6.5 CVE-2023-22833 Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Found… Foundry after 2.531.0 Fix from $1,6002023-06-06 HIGH 7.8 CVE-2023-21670 Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode. 315 5g Iot Modem Firmware Patch available Fix from $1,9502023-06-06 HIGH 7.8 CVE-2022-40529 Memory corruption due to improper access control in kernel while processing a mapping request from root process. Aqt1000 Firmware Mitigation only Fix from $1,9502023-06-06 HIGH 7.8 CVE-2023-3027 The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,9502023-06-05 HIGH 8.1 CVE-2023-3066 Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including admi… Amxgt 100 after 1.3.20 Fix from $1,9502023-06-05 HIGH 8.8 CVE-2023-25729 Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them wi… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 MEDIUM 6.5 CVE-2023-23604 A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have l… Firefox 109.0+ Fix from $1,6002023-06-02 HIGH 8.8 CVE-2023-3033 Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Secur… Mobatime Web Application after 06.7.22 Fix from $1,9502023-06-02 CRITICAL 9.8 CVE-2023-28698 Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can exploit this vulnerability by … Fantsy Mitigation only Fix from $2,3002023-06-02 HIGH 8.8 CVE-2022-46307 SGUDA U-Lock central lock control service’s lock management function has incorrect authorization. A remote attacker with general privilege can exploi… U Lock Firmware Mitigation only Fix from $1,9502023-06-02 HIGH 8.8 CVE-2022-46308 SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can e… U Lock Firmware Mitigation only Fix from $1,9502023-06-02 CRITICAL 9.8 CVE-2023-34218 In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible Teamcity 2023.05+ Fix from $2,3002023-05-31 HIGH 7.4 CVE-2023-28352 An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled arti… Insight No fix yet Fix from $1,9502023-05-31 HIGH 8.8 CVE-2023-33779 A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POS… Xxl Job Mitigation only Fix from $1,9502023-05-26 HIGH 7.5 CVE-2023-31226 The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vulnerability may affect confide… Emui No fix yet Fix from $1,9502023-05-26 MEDIUM 6.8 CVE-2023-2002 A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This f… Linux Kernel 6.4+ Fix from $1,6002023-05-26 HIGH 7.5 CVE-2023-31726 AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information. Alist No fix yet Fix from $1,9502023-05-23 HIGH 7.5 CVE-2023-23299 The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malic… Connect Iq after 4.1.7 Fix from $1,9502023-05-23 CRITICAL 9.1 CVE-2023-23304 The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.Sensor… Connect Iq after 4.1.7 Fix from $2,3002023-05-23 HIGH 8.8 CVE-2023-25946 Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent attacker to analyze the product… Q Sl2 Firmware after 2.0.9 Fix from $1,9502023-05-23 CRITICAL 9.8 CVE-2023-27388 Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login t… Tr 71w Firmware Mitigation only Fix from $2,3002023-05-23 MEDIUM 6.5 CVE-2023-33254 There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a high… Kace Systems Deployment Appliance No fix yet Fix from $1,6002023-05-21 MEDIUM 5.5 CVE-2023-26818 Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag. Telegram No fix yet Fix from $1,6002023-05-19 MEDIUM 6.5 CVE-2023-31597 An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user. At… Zammad 5.4.1+ Fix from $1,6002023-05-18 MEDIUM 5.5 CVE-2023-2782 Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build … Cyber Infrastructure 5.3.1-38+ Fix from $1,6002023-05-18 MEDIUM 6.7 CVE-2023-21116 In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logi… Android Patch available Fix from $1,6002023-05-15 HIGH 7.8 CVE-2023-21117 In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receiver due to… Android Patch available Fix from $1,9502023-05-15