Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2023-23918 A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Perm… Node.js 14.21.3 / 16.19.1+ Fix from $1,9502023-02-23 CRITICAL 9.8 CVE-2023-23064 TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control. A720r Firmware No fix yet Fix from $2,3002023-02-17 CRITICAL 9.8 CVE-2021-32163 Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization. Modular Open Smart Network 0.23.0+ Fix from $2,3002023-02-17 HIGH 7.8 CVE-2023-24485 Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix… Workspace 2212+ Fix from $1,9502023-02-16 HIGH 8.5 CVE-2023-23947 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2… Argo Cd 2.3.17 / 2.4.23+ Fix from $1,9502023-02-16 HIGH 7.8 CVE-2023-25173 containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not … Containerd 1.5.18 / 1.6.18+ Fix from $1,9502023-02-16 HIGH 7.3 CVE-2023-21715 KEVEPSS 12% Microsoft Publisher Security Feature Bypass Vulnerability 365 Apps Patch available Fix from $1,9502023-02-14 MEDIUM 6.5 CVE-2023-0814 The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_met… Profile Builder after 3.9.0 Fix from $1,6002023-02-14 MEDIUM 5.7 CVE-2022-34397 Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerabi… Evasa Provider Virtual Appliance 9.2.3.6 / 9.2.3.22+ Fix from $1,6002023-02-13 HIGH 8.1 CVE-2023-25559 DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata… Datahub 0.8.45+ Fix from $1,9502023-02-11 MEDIUM 5.5 CVE-2023-21423 Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission… Android Mitigation only Fix from $1,6002023-02-09 MEDIUM 5.5 CVE-2023-21422 Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server w… Android Mitigation only Fix from $1,6002023-02-09 HIGH 8.8 CVE-2022-45544 Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the t… Cms No fix yet Fix from $1,9502023-02-07 HIGH 7.8 CVE-2023-23696 Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious user… Command \| Intel Vpro Out Of Band 4.4.0+ Fix from $1,9502023-02-07 HIGH 7.2 CVE-2023-24029 In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to ins… Ws Ftp Server 8.8+ Fix from $1,9502023-02-03 CRITICAL 9.8 CVE-2022-47002EPSS 6% A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request. Masacms 7.2.5 / 7.3.10+ Fix from $2,3002023-02-01 CRITICAL 9.8 CVE-2023-23924 Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letter… Dompdf Patch available Fix from $2,3002023-02-01 CRITICAL 9.8 CVE-2022-45172 An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endp… Vdesk 018+ Fix from $2,3002023-01-31 HIGH 7.5 CVE-2023-22610 A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are se… Ecostruxure Geo Scada Expert 2019 Patch available Fix from $1,9502023-01-31 MEDIUM 6.5 CVE-2022-45435 IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve… Identityiq 8.0+ Fix from $1,6002023-01-31 HIGH 8.8 CVE-2023-24829 Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 bef… Iotdb 0.13.3+ Fix from $1,9502023-01-31 HIGH 8.8 CVE-2023-22482 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6… Argo Cd 2.3.14 / 2.4.20+ Fix from $1,9502023-01-26 HIGH 7.5 CVE-2023-22500 GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to Incorrect Authorization. This v… Glpi 10.0.6+ Fix from $1,9502023-01-26 MEDIUM 6.5 CVE-2023-21719 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Edge Chromium 109.0.1518.70+ Fix from $1,6002023-01-24 MEDIUM 6.5 CVE-2023-20018 A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker t… Ip Phone 7800 Firmware 14.1+ Fix from $1,6002023-01-20 CRITICAL 9.8 CVE-2022-23739 An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests fr… Enterprise Server 3.3.16 / 3.4.11+ Fix from $2,3002023-01-17 HIGH 8.1 CVE-2022-45353 Broken Access Control in Betheme theme <= 26.6.1 on WordPress. Betheme after 26.6.1 Fix from $1,9502023-01-14 MEDIUM 6.5 CVE-2023-0298 Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0. Firefly Iii 5.8.0+ Fix from $1,6002023-01-14 CRITICAL 9.8 CVE-2023-22480EPSS 67% KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In Kube… Kubeoperator 3.16.4+ Fix from $2,3002023-01-14 HIGH 7.1 CVE-2022-2155 A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on … Lumada Asset Performance Management 6.4.0.1+ Fix from $1,9502023-01-12