Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Wyse Management Suite MEDIUM 5.3
CVE-2022-33931

Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no access to Alert Classificatio…

Fix: 3.8.0+
Fix from $1,600 2022-08-10
Wyse Management Suite MEDIUM 5.3
CVE-2022-33924

Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with no access to create rules co…

Fix: 3.8.0+
Fix from $1,600 2022-08-10
Wyse Management Suite MEDIUM 6.5
CVE-2022-33925

Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could potentiall…

Fix: 3.8.0+
Fix from $1,600 2022-08-10
Wyse Management Suite MEDIUM 6.5
CVE-2022-33926

Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerabilit…

Fix: 3.8.0+
Fix from $1,600 2022-08-10
Cp 8021 Master Module Firmware HIGH 7.5
CVE-2021-46304

A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All version…

Mitigation only
Fix from $1,950 2022-08-10
Company Website\/cms MEDIUM 6.5
CVE-2022-2702

A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of t…

No fix yet
Fix from $1,600 2022-08-08
Linkhub Mesh Wifi Ac1200 CRITICAL 9.8
CVE-2022-26346

A denial of service vulnerability exists in the ucloud_del_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network…

No fix yet
Fix from $2,300 2022-08-05
Linkhub Mesh Wifi Ac1200 CRITICAL 9.8
CVE-2022-27178

A denial of service vulnerability exists in the confctl_set_wan_cfg functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted net…

No fix yet
Fix from $2,300 2022-08-05
Linkhub Mesh Wifi Ac1200 HIGH 7.5
CVE-2022-27185

A denial of service vulnerability exists in the confctl_set_master_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted …

No fix yet
Fix from $1,950 2022-08-05
Linkhub Mesh Wifi Ac1200 HIGH 7.5
CVE-2022-27660

A denial of service vulnerability exists in the confctl_set_guest_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted …

No fix yet
Fix from $1,950 2022-08-05
Eos MEDIUM 6.5
CVE-2021-28511

This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is th…

Fix: after 4.27.3
Fix from $1,600 2022-08-05
Android HIGH 7.1
CVE-2022-33731

Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

Mitigation only
Fix from $1,950 2022-08-05
Tooljet HIGH 8.8
CVE-2022-2631

Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.

Fix: 1.19.0+
Fix from $1,950 2022-08-02
Pandora Fms MEDIUM 5.4
CVE-2022-26308

Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write)…

Fix: after 7.0_ng_760
Fix from $1,600 2022-08-01
Garage Management System CRITICAL 9.8
CVE-2022-2578

A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This issue affects some unknown pro…

No fix yet
Fix from $2,300 2022-07-29
Zulip HIGH 7.5
CVE-2016-4427

In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.

Fix: 1.3.12+
Fix from $1,950 2022-07-28
Vbase Web Remote HIGH 7.5
CVE-2021-38417

VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing ac…

Mitigation only
Fix from $1,950 2022-07-27
Warp HIGH 7.8
CVE-2022-2225

By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust s…

Fix: 2022.5.227.0 / 2022.5.341.0+
Fix from $1,950 2022-07-26
Banking Trade Finance MEDIUM 6.4
CVE-2022-21586

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported versio…

Patch available
Fix from $1,600 2022-07-19
Node.js HIGH 8.1
CVE-2022-32212EPSS 6%

A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easil…

Fix: 1.0 / 14.20.1+
Fix from $1,950 2022-07-14
Argo Cd HIGH 8.8
CVE-2022-1025

All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially esc…

Fix: after 2.3.1
Fix from $1,950 2022-07-12
Mendix HIGH 7.5
CVE-2022-31257

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions…

Fix: 7.32.31 / 8.18.18+
Fix from $1,950 2022-07-12
Unified Communications Manager HIGH 8.8
CVE-2022-20859

A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM &amp…

Fix: 14su2 / 14.0su2+
Fix from $1,950 2022-07-06
Hub MEDIUM 5.3
CVE-2022-34894

In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services

Fix: 2022.2.14799+
Fix from $1,600 2022-07-01
Whale MEDIUM 5.3
CVE-2020-9754

NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.

Fix: 1.10.6.2+
Fix from $1,600 2022-06-27
Sepcos Control And Protection Relay Firmware CRITICAL 9.1
CVE-2022-2103

An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely …

Fix: 1.23.21 / 1.24.8+
Fix from $2,300 2022-06-24
Local Run Manager CRITICAL 9.1
CVE-2022-1521

LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.

Fix: after 3.1
Fix from $2,300 2022-06-24
Adminer Login HIGH 7.8
CVE-2017-20066

A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads …

No fix yet
Fix from $1,950 2022-06-20
Application Delivery Management HIGH 8.1
CVE-2022-27511EPSS 12%

Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device…

Fix: 13.0-85.19 / 13.1-21.53+
Fix from $1,950 2022-06-16
Custom Popup Builder MEDIUM 5.4
CVE-2022-28612

Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabi…

Fix: after 1.3.1
Fix from $1,600 2022-06-15