Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Ldap Connector CRITICAL 9.8
CVE-2022-0143

When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connecto…

Fix: 1.5.20.9+
Fix from $2,300 2022-09-19
Nis Hap11ac Firmware CRITICAL 9.8
CVE-2022-23768

This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all…

Mitigation only
Fix from $2,300 2022-09-19
Cri O HIGH 7.1
CVE-2022-2995

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modifica…

Patch available
Fix from $1,950 2022-09-19
Zoom On Premise Meeting Connector Mmr HIGH 8.2
CVE-2022-28758

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious act…

Fix: 4.8.20220815.130+
Fix from $1,950 2022-09-16
Remote Desktop Manager HIGH 7.0
CVE-2022-3182

Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypas…

Fix: 2022.2.15+
Fix from $1,950 2022-09-13
Cms8000 Firmware MEDIUM 5.7
CVE-2022-3027

The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malici…

Mitigation only
Fix from $1,600 2022-09-13
Cms8000 Firmware MEDIUM 6.8
CVE-2022-36385

A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to…

Mitigation only
Fix from $1,600 2022-09-13
Coreshield One Way Gateway HIGH 7.8
CVE-2022-38466

A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file p…

Fix: 2.2+
Fix from $1,950 2022-09-13
Galaxy Watch Plugin MEDIUM 5.5
CVE-2022-36875

Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the f…

Fix: 2.2.11.22081151+
Fix from $1,600 2022-09-09
Samsung Email HIGH 7.8
CVE-2022-36864

Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute priv…

Fix: 6.1.70.20+
Fix from $1,950 2022-09-09
Editor Lite MEDIUM 5.5
CVE-2022-36867

Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.

Fix: 4.0.40.14+
Fix from $1,600 2022-09-09
Contacts Provider MEDIUM 6.1
CVE-2022-36869

Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file withou…

Fix: 12.7.59+
Fix from $1,600 2022-09-09
Catalyst Sd Wan Manager HIGH 8.8
CVE-2022-20696

A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has ac…

Fix: 20.6.4 / 20.9.1+
Fix from $1,950 2022-09-08
Gocd MEDIUM 5.5
CVE-2022-36088

GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately rest…

Fix: 22.2.0+
Fix from $1,600 2022-09-07
Canna MEDIUM 5.3
CVE-2022-21950

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local u…

Fix: 3.7p3-bp153.2.3.1 / 3.7p3-bp154.3.3.1+
Fix from $1,600 2022-09-07
Drawio HIGH 7.5
CVE-2022-3065

Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.

Fix: 20.2.8+
Fix from $1,950 2022-09-02
Tooljet HIGH 8.8
CVE-2022-3019

The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comme…

Fix: 1.23.0+
Fix from $1,950 2022-08-29
Linux Kernel HIGH 7.0
CVE-2021-3864

A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID bin…

Patch available
Fix from $1,950 2022-08-26
Mac Os X MEDIUM 5.5
CVE-2022-32834

An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 202…

Fix: 10.15.7 / 11.6.8+
Fix from $1,600 2022-08-24
Linux Kernel HIGH 7.8
CVE-2021-4037

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS…

Fix: 5.11+
Fix from $1,950 2022-08-24
Electric\'s Proficy HIGH 7.5
CVE-2022-2792

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a dire…

Fix: after 9.0.0
Fix from $1,950 2022-08-19
Streamlabs Desktop HIGH 7.3
CVE-2022-36263

StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .e…

No fix yet
Fix from $1,950 2022-08-19
Pycord MEDIUM 6.5
CVE-2022-36024

py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to remote shutdown if they are ad…

Patch available
Fix from $1,600 2022-08-18
Commerce HIGH 8.8
CVE-2022-34255

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerabili…

Fix: 2.3.7 / 2.4.3+
Fix from $1,950 2022-08-16
Commerce MEDIUM 5.3
CVE-2022-34259

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerabili…

Fix: 2.3.7 / 2.4.3+
Fix from $1,600 2022-08-16
Collaboration HIGH 7.8
CVE-2022-37393

Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended function…

Patch available
Fix from $1,950 2022-08-16
Portal For Arcgis HIGH 7.5
CVE-2022-38184

There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker…

Fix: after 10.8.1
Fix from $1,950 2022-08-16
Meeting Connector MEDIUM 5.4
CVE-2022-28753

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious act…

Fix: 4.8.129.20220714+
Fix from $1,600 2022-08-11
Meeting Connector MEDIUM 5.4
CVE-2022-28754

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious act…

Fix: 4.8.129.20220714+
Fix from $1,600 2022-08-11
Manageengine Firewall Analyzer HIGH 7.5
CVE-2022-36923EPSS 7%

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 20…

Mitigation only
Fix from $1,950 2022-08-10