Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Fortiproxy CRITICAL 9.8
CVE-2022-35843

An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 thr…

Fix: after 7.0.7
Fix from $2,300 2022-12-06
Goodcloud HIGH 7.4
CVE-2022-44211

In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.

Fix: after 1.0
Fix from $1,950 2022-12-01
Goodcloud MEDIUM 5.9
CVE-2022-44212

In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.

Fix: after 1.0
Fix from $1,600 2022-12-01
Nextcloud Server MEDIUM 5.3
CVE-2022-41970

Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through …

Fix: 24.0.7+
Fix from $1,600 2022-12-01
Book Store Management System CRITICAL 9.8
CVE-2022-4229

A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability affects unknown code of the f…

No fix yet
Fix from $2,300 2022-11-30
Ecu C Firmware HIGH 8.8
CVE-2022-44037

An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allows attacke…

No fix yet
Fix from $1,950 2022-11-29
Tiny File Manager MEDIUM 6.5
CVE-2022-45475

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the ap…

No fix yet
Fix from $1,600 2022-11-25
Zxa10 C350m Firmware CRITICAL 9.8
CVE-2022-39070

There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulner…

Fix: 2.1.0xgp002.4+
Fix from $2,300 2022-11-22
Iq Block Country CRITICAL 9.8
CVE-2022-41155

Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.

Fix: 1.2.19+
Fix from $2,300 2022-11-19
Customizable Wordpress Gallery Plugin Modula Image Gallery MEDIUM 5.3
CVE-2022-41135

Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.

Fix: 2.6.91+
Fix from $1,600 2022-11-18
Better Messages MEDIUM 6.5
CVE-2022-40216

Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.

Fix: 1.9.10.71+
Fix from $1,600 2022-11-18
Boss Mini Firmware CRITICAL 9.9
CVE-2022-34827

Carel Boss Mini 1.5.0 has Improper Access Control.

No fix yet
Fix from $2,300 2022-11-18
Quiz And Survey Master CRITICAL 9.8
CVE-2022-41652

Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

Fix: 7.3.11+
Fix from $2,300 2022-11-18
Infraskope Siem\+ MEDIUM 6.5
CVE-2022-24038

Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page w…

Fix: 7.10.00+
Fix from $1,600 2022-11-18
Infraskope Siem\+ HIGH 8.6
CVE-2022-24036

Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs.

Fix: 7.10.00+
Fix from $1,950 2022-11-16
Firepower Services Software For Asa HIGH 7.5
CVE-2022-20918

A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) F…

Fix: 7.0.5+
Fix from $1,950 2022-11-15
Aqt1000 Firmware MEDIUM 5.5
CVE-2022-25679

Denial of service in video due to improper access control in broadcast receivers in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industria…

Mitigation only
Fix from $1,600 2022-11-15
Nuc 10 Performance Kit Nuc10i7fnhn Firmware HIGH 7.8
CVE-2022-36789

Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML357.0…

Mitigation only
Fix from $1,950 2022-11-11
Nuc 8 Compute Element Cm8i7cb Firmware MEDIUM 6.7
CVE-2022-35276

Improper access control in BIOS firmware for some Intel(R) NUC 8 Compute Elements before version CBWHL357.0096 may allow a privileged user to potenti…

Patch available
Fix from $1,600 2022-11-11
Owncloud MEDIUM 5.3
CVE-2022-43679

The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused t…

Fix: after 10.11.0
Fix from $1,600 2022-11-10
Workspace One Assist CRITICAL 9.8
CVE-2022-31687

VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Ass…

Fix: 22.10+
Fix from $2,300 2022-11-09
Amd Link HIGH 7.5
CVE-2022-27673

Insufficient access controls in the AMD Link Android app may potentially result in information disclosure.

Fix: 5.0.220614+
Fix from $1,950 2022-11-09
Emui CRITICAL 9.8
CVE-2021-46851

The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video …

No fix yet
Fix from $2,300 2022-11-09
Enterprise Driver HIGH 7.8
CVE-2021-26360

An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow …

Fix: 22.q2 / 22.5.2+
Fix from $1,950 2022-11-09
Inrouter302 Firmware CRITICAL 9.8
CVE-2022-25932

The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker c…

Fix: 3.5.56+
Fix from $2,300 2022-11-09
Mahara HIGH 7.5
CVE-2022-42707

In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a suffic…

Fix: 21.04.7 / 21.10.5+
Fix from $1,950 2022-11-06
Infosphere Information Server MEDIUM 6.5
CVE-2022-22442

"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to i…

Patch available
Fix from $1,600 2022-11-03
Teamcity MEDIUM 5.3
CVE-2022-44622

In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive

Fix: 2022.10+
Fix from $1,600 2022-11-03
Ipados MEDIUM 5.5
CVE-2022-42811

An access issue was addressed with additional sandbox restrictions. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watch…

Fix: 9.1 / 13.0+
Fix from $1,600 2022-11-01
macOS MEDIUM 5.5
CVE-2022-42814

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

Fix: 13.0+
Fix from $1,600 2022-11-01