Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Zoom On Premise Meeting Connector Mmr MEDIUM 6.5
CVE-2022-28761

Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious act…

Fix: 4.8.20220916.131+
Fix from $1,600 2022-10-14
Zoom On Premise Meeting Connector Mmr HIGH 8.6
CVE-2022-28759

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious act…

Fix: 4.8.20220815.130+
Fix from $1,950 2022-10-14
Vagrant HIGH 7.8
CVE-2022-42717

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has bee…

Fix: 2.3.1+
Fix from $1,950 2022-10-11
Redirection For Contact Form 7 HIGH 7.5
CVE-2021-36913

Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows att…

Fix: 2.6.0+
Fix from $1,950 2022-10-11
Hybrid Client MEDIUM 6.5
CVE-2022-34431

Dell Hybrid Client below 1.8 version contains a guest user profile corruption vulnerability. A WMS privilege attacker could potentially exploit this …

Fix: 1.8+
Fix from $1,600 2022-10-11
Navigator Mobile MEDIUM 5.5
CVE-2022-38388

IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to improper access control. IBM X-F…

Patch available
Fix from $1,600 2022-10-11
Group Sharing MEDIUM 5.3
CVE-2022-39877

Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(…

Fix: 13.0.6.14 / 13.0.6.15+
Fix from $1,600 2022-10-07
Checkout MEDIUM 5.5
CVE-2022-39878

Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via implicit int…

Fix: 5.0.55.3+
Fix from $1,600 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39867

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39868

Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information …

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39869

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39870

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39871

Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39864

Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive informa…

Fix: 1.7.85.25+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39865

Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive info…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39866

Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inform…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Factorycamerafb MEDIUM 5.5
CVE-2022-39857

Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent…

Fix: 3.5.51+
Fix from $1,600 2022-10-07
Android HIGH 7.8
CVE-2022-39854

Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.

Mitigation only
Fix from $1,950 2022-10-07
Applock MEDIUM 6.6
CVE-2022-1959

AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is possible because the applica…

No fix yet
Fix from $1,600 2022-09-30
Qradar User Behavior Analytics MEDIUM 6.5
CVE-2022-36771

IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-…

Fix: 4.1.9+
Fix from $1,600 2022-09-28
Gajim MEDIUM 5.3
CVE-2022-39835

An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent b…

Fix: 1.5.0+
Fix from $1,600 2022-09-27
Scadapro Server HIGH 7.8
CVE-2022-3263

The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileg…

Mitigation only
Fix from $1,950 2022-09-23
macOS MEDIUM 5.5
CVE-2022-32848

A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to capture a u…

Fix: 11.6.8 / 12.5+
Fix from $1,600 2022-09-23
macOS MEDIUM 5.5
CVE-2022-32783

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An app may gain unauthorized access to Bluetooth.

Fix: 12.4+
Fix from $1,600 2022-09-23
macOS MEDIUM 5.5
CVE-2022-32789

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to bypass Privacy preferences.

Fix: 12.5+
Fix from $1,600 2022-09-23
Mac Os X MEDIUM 5.5
CVE-2022-32800

This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. A…

Fix: 10.15.7 / 11.6.8+
Fix from $1,600 2022-09-23
Evohclaimable MEDIUM 5.3
CVE-2022-35621

Access control vulnerability in Evoh NFT EvohClaimable contract with sha256 hash code fa2084d5abca91a62ed1d2f1cad3ec318e6a9a2d7f1510a00d898737b05f48a…

No fix yet
Fix from $1,600 2022-09-21
Wildfly Deployer MEDIUM 5.3
CVE-2022-41235

Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins control…

Fix: after 1.0.2
Fix from $1,600 2022-09-21
macOS MEDIUM 6.5
CVE-2022-32880

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to access user-sensitive data.

Fix: 12.5+
Fix from $1,600 2022-09-20
Ipados MEDIUM 5.5
CVE-2022-32883

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 1…

Fix: 9.0 / 11.7+
Fix from $1,600 2022-09-20