Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Rdiffweb CRITICAL 9.8
CVE-2022-4724

Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.

Fix: 2.5.5+
Fix from $2,300 2022-12-27
Lieferantenmanager MEDIUM 6.5
CVE-2022-44014

An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to fetch arbitrary SQL tables. …

Fix: 5.6+
Fix from $1,600 2022-12-25
Airfiber Gigabeam Firmware MEDIUM 5.3
CVE-2022-44565

An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 tha…

Fix: 1.0.0 / 1.4.1+
Fix from $1,600 2022-12-23
Memos HIGH 8.8
CVE-2022-4689

Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

Fix: 0.9.0+
Fix from $1,950 2022-12-23
Memos HIGH 8.8
CVE-2022-4684

Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

Fix: 0.9.0+
Fix from $1,950 2022-12-23
Adminlte MEDIUM 5.3
CVE-2022-23513EPSS 40%

Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the thre…

Fix: after 5.17
Fix from $1,600 2022-12-23
Iboot Pdu4 N20 Firmware HIGH 7.5
CVE-2022-3186

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s m…

Fix: 1.42.06162022+
Fix from $1,950 2022-12-21
Bigfix Webui MEDIUM 5.8
CVE-2022-38655

BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from…

Mitigation only
Fix from $1,600 2022-12-21
Nbg7510 Firmware CRITICAL 9.8
CVE-2022-38546

A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker to access…

Fix: after 1.00
Fix from $2,300 2022-12-21
Enterprise Metrics HIGH 8.8
CVE-2022-44643

A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an acce…

Fix: 1.7.1 / 2.3.1+
Fix from $1,950 2022-12-20
Ds 3wf0ac 2nt Firmware CRITICAL 9.8
CVE-2022-28173

The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permission. The …

Fix: 1.0.4 / 1.1.0+
Fix from $2,300 2022-12-19
Openemr HIGH 8.1
CVE-2022-4567

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.

Fix: 7.0.0.2+
Fix from $1,950 2022-12-17
Symantec Identity Governance And Administration MEDIUM 6.7
CVE-2022-25627

An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Id…

Mitigation only
Fix from $1,600 2022-12-16
Ipados MEDIUM 5.5
CVE-2022-42859

Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An …

Fix: 9.2 / 13.1+
Fix from $1,600 2022-12-15
Ipados HIGH 8.8
CVE-2022-42861

This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2…

Fix: 12.6.2 / 15.7.2+
Fix from $1,950 2022-12-15
Ipados MEDIUM 5.5
CVE-2022-42862

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to …

Fix: 13.1 / 16.2+
Fix from $1,600 2022-12-15
Ipados MEDIUM 5.5
CVE-2022-42865

This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A…

Fix: 9.2 / 13.1+
Fix from $1,600 2022-12-15
macOS MEDIUM 5.5
CVE-2022-42853

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.1. An app may be able to modify protected pa…

Fix: 13.1+
Fix from $1,600 2022-12-15
Master Quiz MEDIUM 6.5
CVE-2022-47407

An issue was discovered in the fp_masterquiz (aka Master-Quiz) extension before 2.2.1, and 3.x before 3.5.1, for TYPO3. An attacker can continue the …

Fix: 2.2.1 / 3.5.1+
Fix from $1,600 2022-12-14
Svmpc1 MEDIUM 5.5
CVE-2022-38355

Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to attackers with access to the local area network (LAN) t…

Fix: after 2.1.22
Fix from $1,600 2022-12-13
Mendix Workflow Commons HIGH 8.1
CVE-2022-46664

A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (All versions < V2.1.4), Mendix …

Fix: 2.4.0+
Fix from $1,950 2022-12-13
6gk5204 0ba00 2mb2 Firmware MEDIUM 5.3
CVE-2022-46354

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204R…

Fix: 3.2.7+
Fix from $1,600 2022-12-13
Mendix Email Connector HIGH 8.1
CVE-2022-45936

A vulnerability has been identified in Mendix Email Connector (All versions < V2.0.0). Affected versions of the module improperly handle access contr…

Fix: 2.0.0+
Fix from $1,950 2022-12-13
Pxc00 E96.a Firmware MEDIUM 6.5
CVE-2022-45937

A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20)…

Fix: 2.8.20 / 3.5.5+
Fix from $1,600 2022-12-13
Solution Manager MEDIUM 5.5
CVE-2022-41261

SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data…

Mitigation only
Fix from $1,600 2022-12-12
Calendar MEDIUM 5.5
CVE-2022-39915

Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Androi…

Fix: 11.6.08.0 / 12.2.11.3000+
Fix from $1,600 2022-12-08
A18 Firmware HIGH 7.5
CVE-2022-44932

An access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service.

No fix yet
Fix from $1,950 2022-12-08
Airwave HIGH 8.1
CVE-2022-37916

Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. T…

Fix: after 8.2.15.0
Fix from $1,950 2022-12-08
Airwave HIGH 8.1
CVE-2022-37917

Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. T…

Fix: after 8.2.15.0
Fix from $1,950 2022-12-08
Airwave HIGH 8.1
CVE-2022-37918

Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. T…

Fix: after 8.2.15.0
Fix from $1,950 2022-12-08