Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Ipados MEDIUM 5.5
CVE-2022-32946

This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair o…

Fix: 16.0 / 16.1+
Fix from $1,600 2022-11-01
macOS MEDIUM 5.5
CVE-2022-32904

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6.…

Fix: 11.7 / 12.6+
Fix from $1,600 2022-11-01
Iphone Os MEDIUM 5.5
CVE-2022-32918

This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to bypass Privacy prefere…

Fix: 13.0 / 16.0+
Fix from $1,600 2022-11-01
Remote Desktop Manager HIGH 7.5
CVE-2022-3780

Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users …

Fix: 2022.3.8+
Fix from $1,950 2022-11-01
Fedora HIGH 7.1
CVE-2022-42327

x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the gl…

Patch available
Fix from $1,950 2022-11-01
Nextcloud Enterprise Server MEDIUM 5.3
CVE-2022-39329

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server pri…

Fix: 23.0.9 / 24.0.5+
Fix from $1,600 2022-10-27
Nessus MEDIUM 6.5
CVE-2022-33757

An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead …

Fix: 10.2.0+
Fix from $1,600 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.8
CVE-2022-27805

An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A…

Mitigation only
Fix from $2,300 2022-10-25
Iac Ast2500a Firmware HIGH 7.5
CVE-2021-44467

A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrarily terminate active sessions …

Mitigation only
Fix from $1,950 2022-10-24
Iac Ast2500a Firmware MEDIUM 5.3
CVE-2021-44776

A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbitrarily change the security ac…

Mitigation only
Fix from $1,600 2022-10-24
Iac Ast2500a Firmware MEDIUM 5.3
CVE-2021-26732

A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network conf…

Mitigation only
Fix from $1,600 2022-10-24
Iac Ast2500a Firmware HIGH 7.5
CVE-2021-26733

A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot comman…

Mitigation only
Fix from $1,950 2022-10-24
Tug Home Base Server HIGH 8.2
CVE-2022-1066

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

Fix: 24+
Fix from $1,950 2022-10-21
Tug Home Base Server HIGH 7.5
CVE-2022-26423

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

Fix: 24+
Fix from $1,950 2022-10-21
Clustered Data Ontap HIGH 8.1
CVE-2022-23241

Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an aut…

Mitigation only
Fix from $1,950 2022-10-19
Compuware Topaz For Total Test HIGH 7.5
CVE-2022-43429

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, …

Fix: after 2.4.8
Fix from $1,950 2022-10-19
Ocomon HIGH 7.5
CVE-2022-40798

OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct …

Fix: 4.0+
Fix from $1,950 2022-10-19
Access Manager MEDIUM 5.3
CVE-2022-39405

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The supported version that is affe…

Patch available
Fix from $1,600 2022-10-18
Peoplesoft Enterprise Common Components HIGH 8.1
CVE-2022-39406

Vulnerability in the PeopleSoft Enterprise Common Components product of Oracle PeopleSoft (component: Approval Framework). The supported version that…

Patch available
Fix from $1,950 2022-10-18
Vm Virtualbox HIGH 7.3
CVE-2022-39421

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4…

Fix: 6.1.40+
Fix from $1,950 2022-10-18
Zgr Tps200 Ng Firmware HIGH 8.1
CVE-2020-8973

ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed requests. This allows an attacke…

Mitigation only
Fix from $1,950 2022-10-17
Factorytalk Vantagepoint HIGH 8.8
CVE-2022-38743

Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The Fac…

Mitigation only
Fix from $1,950 2022-10-17
Robot System Software HIGH 7.5
CVE-2022-3382

HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an attacker could craft code to…

Mitigation only
Fix from $1,950 2022-10-17
GitLab MEDIUM 5.4
CVE-2022-3066

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all ve…

Fix: 15.2.5 / 15.3.4+
Fix from $1,600 2022-10-17
GitLab MEDIUM 6.5
CVE-2022-3067

An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starti…

Fix: 15.2.5 / 15.3.4+
Fix from $1,600 2022-10-17
GitLab MEDIUM 5.3
CVE-2022-3286

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a gr…

Fix: 15.2.5 / 15.3.4+
Fix from $1,600 2022-10-17
Job Order Interface CRITICAL 9.8
CVE-2022-2052

Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gai…

Fix: after 1.6
Fix from $2,300 2022-10-17
Gocd MEDIUM 6.5
CVE-2022-39310

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go…

Fix: 21.1.0+
Fix from $1,600 2022-10-14
Commerce MEDIUM 5.3
CVE-2022-35689

Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in …

Fix: 2.4.4+
Fix from $1,600 2022-10-14
Zoom On Premise Meeting Connector Mmr MEDIUM 6.5
CVE-2022-28760

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious act…

Fix: 4.8.20220815.130+
Fix from $1,600 2022-10-14