Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 8.8 CVE-2022-27642 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers.… Cax80 Firmware 1.0.1.78 / 1.0.4.126+ Fix from $1,9502023-03-29 HIGH 8.8 CVE-2023-1144 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the… Infrasuite Device Master 1.0.5+ Fix from $1,9502023-03-27 HIGH 7.5 CVE-2023-1136 In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to … Infrasuite Device Master 1.0.5+ Fix from $1,9502023-03-27 HIGH 8.1 CVE-2023-25017 RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote attacker with general user privilege is allowed to perform … Iot Wall Mitigation only Fix from $1,9502023-03-27 HIGH 7.8 CVE-2023-21034 In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local … Android Patch available Fix from $1,9502023-03-24 HIGH 7.8 CVE-2023-21035 In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same pac… Android Patch available Fix from $1,9502023-03-24 HIGH 7.8 CVE-2023-20975 In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due to a permis… Android Mitigation only Fix from $1,9502023-03-24 HIGH 7.8 CVE-2023-20971 In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic… Android Mitigation only Fix from $1,9502023-03-24 CRITICAL 9.8 CVE-2023-28611 Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access res… Stationguard after 2.20 Fix from $2,3002023-03-23 HIGH 7.2 CVE-2023-23192 IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task. Userlock No fix yet Fix from $1,9502023-03-23 HIGH 8.8 CVE-2023-25594 A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions tha… Clearpass Policy Manager after 6.10.8 Fix from $1,9502023-03-22 HIGH 8.8 CVE-2023-25924 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not… Security Key Lifecycle Manager Patch available Fix from $1,9502023-03-22 HIGH 7.5 CVE-2023-25923 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of… Security Key Lifecycle Manager Patch available Fix from $1,9502023-03-21 HIGH 7.5 CVE-2023-27578 Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an… Galaxy 22.01+ Fix from $1,9502023-03-20 HIGH 8.8 CVE-2023-0940 The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. Th… Profilegrid 5.3.1+ Fix from $1,9502023-03-20 HIGH 7.3 CVE-2023-27594 Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, under speci… Cilium 1.11.15 / 1.12.8+ Fix from $1,9502023-03-17 HIGH 8.2 CVE-2023-26484 KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has taken over a Kubernetes node wh… Kubevirt after 0.59.0 Fix from $1,9502023-03-15 HIGH 7.5 CVE-2022-39214EPSS 26% Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able … Itop 2.7.8 / 3.0.2-1+ Fix from $1,9502023-03-14 HIGH 8.1 CVE-2023-24999 HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the s… Vault 1.10.11 / 1.11.8+ Fix from $1,9502023-03-11 HIGH 7.0 CVE-2023-27899 Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly… Jenkins 2.375.4 / 2.394+ Fix from $1,9502023-03-10 MEDIUM 6.5 CVE-2022-4315 An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with … Dynamic Application Security Testing Analyzer 3.0.55+ Fix from $1,6002023-03-08 HIGH 8.1 CVE-2023-22891 There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset … Zephyr Enterprise after 7.15 Fix from $1,9502023-03-08 HIGH 8.8 CVE-2023-27486 xCAT is a toolkit for deployment and administration of computer clusters. In versions prior to 2.16.5 if zones are configured as a mechanism to secur… Xcat 2.16.5+ Fix from $1,9502023-03-08 HIGH 7.8 CVE-2023-1164 A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is some unknown functionality o… Kylin Os 1.3.11-23 / 1.30.10-5.p23+ Fix from $1,9502023-03-03 MEDIUM 5.4 CVE-2023-26056 XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, pro… Xwiki 13.10.10 / 14.4.5+ Fix from $1,6002023-03-02 MEDIUM 6.5 CVE-2023-0952 Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without … Devolutions Server after 2022.3.12 Fix from $1,6002023-03-01 MEDIUM 6.5 CVE-2023-25575 API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the… Core 2.7.10 / 3.0.12+ Fix from $1,6002023-02-28 MEDIUM 5.5 CVE-2023-23510 A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access a user’s Safari h… macOS 13.2+ Fix from $1,6002023-02-27 MEDIUM 5.5 CVE-2023-23506 A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access user-sensitive da… macOS 13.2+ Fix from $1,6002023-02-27 MEDIUM 5.5 CVE-2022-46704 A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, macOS Big Sur 11.7.2, macOS Monterey 12.6.2. A… macOS 11.7.2 / 12.6.2+ Fix from $1,6002023-02-27