Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2023-23445 Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivi… Ftmg Esd20axx Firmware 2.0+ Fix from $1,9502023-05-15 HIGH 7.5 CVE-2023-23446 Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivi… Ftmg Esd20axx Firmware 2.0+ Fix from $1,9502023-05-15 HIGH 8.8 CVE-2023-20877 VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execu… Cloud Foundation after 4.5 Fix from $1,9502023-05-12 MEDIUM 6.7 CVE-2023-20880 VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate p… Aria Operations 8.12.0+ Fix from $1,6002023-05-12 MEDIUM 5.5 CVE-2023-29818 An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the def… Secureanywhere after 9.0.33.39 Fix from $1,6002023-05-12 MEDIUM 5.5 CVE-2023-29819 An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a craft… Secureanywhere after 9.0.33.39 Fix from $1,6002023-05-12 HIGH 8.8 CVE-2023-2515 Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to syst… Mattermost Server 7.1.8 / 7.7.4+ Fix from $1,9502023-05-12 MEDIUM 6.5 CVE-2023-28325 An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMes… Rocket.chat 6.0.0+ Fix from $1,6002023-05-11 MEDIUM 5.5 CVE-2022-45128 Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service vi… Endpoint Management Assistant 1.9.0.0+ Fix from $1,6002023-05-10 MEDIUM 5.5 CVE-2022-43465 Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local ac… Setup And Configuration Software Mitigation only Fix from $1,6002023-05-10 MEDIUM 5.5 CVE-2022-41610 Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated… Endpoint Management Assistant Configuration Tool 1.0.4 / 2.4+ Fix from $1,6002023-05-10 MEDIUM 6.7 CVE-2023-24932EPSS 11% Secure Boot Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.19926 / 10.0.14393.5921+ Fix from $1,6002023-05-09 HIGH 8.8 CVE-2023-32069 XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user … Xwiki 14.10.4+ Fix from $1,9502023-05-09 HIGH 7.1 CVE-2020-23362 Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter. Yershop No fix yet Fix from $1,9502023-05-09 MEDIUM 6.5 CVE-2023-31138 DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to version… Dhis 2 2.37.9.1 / 2.38.3.1+ Fix from $1,6002023-05-09 MEDIUM 6.5 CVE-2023-32060 DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to version… Dhis 2 2.36.13 / 2.37.8+ Fix from $1,6002023-05-09 MEDIUM 5.9 CVE-2023-31141 OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10 and 2.7.0, there is an issue… Opensearch 1.3.10 / 2.7.0+ Fix from $1,6002023-05-08 HIGH 7.5 CVE-2023-24505 Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request. Ncr\/camera Firmware No fix yet Fix from $1,9502023-05-08 MEDIUM 5.5 CVE-2023-27951 The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An archive may … macOS 11.7.5 / 12.6.4+ Fix from $1,6002023-05-08 MEDIUM 6.5 CVE-2023-27954 The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 … Safari 9.4 / 13.3+ Fix from $1,6002023-05-08 MEDIUM 5.5 CVE-2023-23538 A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. An app may be able to modify prot… macOS 12.6.4 / 13.3+ Fix from $1,6002023-05-08 HIGH 7.8 CVE-2023-30840 Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-intensive applications. Starting in version 0.7.0… Fluid 0.8.6+ Fix from $1,9502023-05-08 MEDIUM 6.5 CVE-2023-1979 The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only ac… Web Stories 1.32.0+ Fix from $1,6002023-05-08 HIGH 8.1 CVE-2023-2534 Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and… Otrs 8.0.32+ Fix from $1,9502023-05-08 MEDIUM 5.4 CVE-2023-29240 An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note:… Big Iq Centralized Management 8.3.0+ Fix from $1,6002023-05-03 HIGH 8.1 CVE-2023-31435 Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire previews) in evasys before 8.2… Evasys No fix yet Fix from $1,9502023-05-02 MEDIUM 6.5 CVE-2022-47874EPSS 21% Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class '… Cloud No fix yet Fix from $1,6002023-05-02 MEDIUM 6.6 CVE-2023-30024 The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access… A921 Firmware No fix yet Fix from $1,6002023-04-28 CRITICAL 9.8 CVE-2023-30467 This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to i… Ms N5008 Uc Firmware 71.9.0.18-r2 / 73.9.0.18-r2+ Fix from $2,3002023-04-28 MEDIUM 5.3 CVE-2022-25091 Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be disclosed by unauthenticated use… Ultimate Bulletin Board after 5.47a Fix from $1,6002023-04-27