Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.8 CVE-2022-37326 Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by co… Desktop 4.6.0+ Fix from $1,9502023-04-27 HIGH 7.8 CVE-2023-26244 An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, which is … Gen5w L Firmware No fix yet Fix from $1,9502023-04-27 HIGH 7.8 CVE-2023-26245 An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is u… Gen5w L Firmware No fix yet Fix from $1,9502023-04-27 HIGH 7.8 CVE-2023-26246 An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is u… Gen5w L Firmware No fix yet Fix from $1,9502023-04-27 HIGH 8.8 CVE-2023-27107 Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows use… Central Server 8.2+ Fix from $1,9502023-04-26 MEDIUM 6.5 CVE-2023-31250 The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files t… Drupal 7.96 / 9.4.14+ Fix from $1,6002023-04-26 MEDIUM 5.4 CVE-2022-25274 Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, r… Drupal 9.3.12+ Fix from $1,6002023-04-26 HIGH 7.8 CVE-2023-20871 VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate … Fusion 13.0.2+ Fix from $1,9502023-04-25 MEDIUM 6.5 CVE-2023-24512 On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to updat… Eos 4.26.10m / 4.27.9m+ Fix from $1,6002023-04-25 HIGH 7.5 CVE-2021-23203 Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to do… Odoo Patch available Fix from $1,9502023-04-25 HIGH 7.8 CVE-2023-2257 Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker wit… Workspace 2023.1.1.4+ Fix from $1,9502023-04-24 MEDIUM 5.5 CVE-2023-26097 An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify the application behaviour may not be blocked. Apsal No fix yet Fix from $1,6002023-04-24 HIGH 7.8 CVE-2023-20950 In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendingIntent. … Android Patch available Fix from $1,9502023-04-19 HIGH 8.8 CVE-2023-25547 A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using … Struxureware Data Center Expert after 7.9.2 Fix from $1,9502023-04-18 MEDIUM 6.5 CVE-2023-25548 A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly se… Struxureware Data Center Expert after 7.9.2 Fix from $1,6002023-04-18 CRITICAL 9.8 CVE-2023-30771 Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd… Iotdb Web Workbench Mitigation only Fix from $2,3002023-04-17 HIGH 8.6 CVE-2020-17354 LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangero… Lilypond 2.24.0+ Fix from $1,9502023-04-15 HIGH 7.5 CVE-2023-22620 An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an inva… Unified Threat Management 12.2.5.1+ Fix from $1,9502023-04-12 MEDIUM 6.8 CVE-2023-28270 Windows Lock Screen Security Feature Bypass Vulnerability Windows 10 1809 10.0.17763.4252 / 10.0.19042.2846+ Fix from $1,6002023-04-11 MEDIUM 6.8 CVE-2023-28249 Windows Boot Manager Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.19869 / 10.0.14393.5850+ Fix from $1,6002023-04-11 MEDIUM 5.3 CVE-2023-25415 Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration. Pe8108 Firmware No fix yet Fix from $1,6002023-04-11 HIGH 7.8 CVE-2022-40682 A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to exec… Forticlient 7.0.8+ Fix from $1,9502023-04-11 HIGH 8.1 CVE-2022-43770 Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in … Pentaho Business Analytics 8.3.0.27 / 9.2.0.4+ Fix from $1,9502023-04-11 MEDIUM 5.3 CVE-2023-0319 An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all ve… GitLab 15.8.5 / 15.9.4+ Fix from $1,6002023-04-05 HIGH 8.8 CVE-2023-28634 GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technic… Glpi 9.5.13 / 10.0.7+ Fix from $1,9502023-04-05 HIGH 8.8 CVE-2022-43940 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization chec… Vantara Pentaho Business Analytics Server 9.3.0.2+ Fix from $1,9502023-04-03 MEDIUM 6.5 CVE-2023-1202 Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows us… Remote Desktop Manager 2023.1.10+ Fix from $1,6002023-04-02 MEDIUM 6.5 CVE-2023-1603 Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restri… Devolutions Server 2023.1.3.0+ Fix from $1,6002023-04-02 CRITICAL 9.8 CVE-2023-23594 An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unaut… Cl4nx Plus Firmware 1.13.3-u724_r2+ Fix from $2,3002023-03-31 CRITICAL 9.8 CVE-2023-26829 An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new … Centrestack 13.5.9808+ Fix from $2,3002023-03-31