Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Splunk CRITICAL 10.0
CVE-2022-32158

Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients t…

Fix: 9.0+
Fix from $2,300 2022-06-15
Filecloud MEDIUM 6.5
CVE-2022-1958

A vulnerability classified as critical has been found in FileCloud. Affected is an unknown function of the component NTFS Handler. The manipulation l…

Fix: 21.3.5.18513+
Fix from $1,600 2022-06-15
Sinema Remote Connect Server MEDIUM 5.3
CVE-2022-32255

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that la…

Fix: 3.1+
Fix from $1,600 2022-06-14
Sinema Remote Connect Server MEDIUM 6.5
CVE-2022-32256

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that la…

Fix: 3.1+
Fix from $1,600 2022-06-14
Kctf HIGH 7.5
CVE-2022-31055

kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was bro…

Fix: 1.6.0+
Fix from $1,950 2022-06-13
Jupiter MEDIUM 5.4
CVE-2022-1658

Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber r…

Fix: after 6.10.1
Fix from $1,600 2022-06-13
Jupiterx HIGH 7.3
CVE-2022-1659

Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which can be used to call any functio…

Fix: after 2.0.6
Fix from $1,950 2022-06-13
Jupiter X Core MEDIUM 5.4
CVE-2022-1656

Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions regist…

Fix: after 2.0.6
Fix from $1,600 2022-06-13
Quick Share MEDIUM 5.5
CVE-2022-30745

Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share.

Fix: 13.1.2.4+
Fix from $1,600 2022-06-07
Android MEDIUM 5.3
CVE-2022-30715

Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.

Mitigation only
Fix from $1,600 2022-06-07
Richdocuments MEDIUM 6.5
CVE-2022-31024

richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user…

Fix: 4.2.6 / 5.0.4+
Fix from $1,600 2022-06-02
Matrikon Opc Server HIGH 8.8
CVE-2022-1261

Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to …

Mitigation only
Fix from $1,950 2022-05-26
Artifactory MEDIUM 6.5
CVE-2021-41834

JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged…

Fix: 6.23.38 / 7.28.0+
Fix from $1,600 2022-05-23
Domino HIGH 7.8
CVE-2020-4107

HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this …

Mitigation only
Fix from $1,950 2022-05-19
Gpu Display Driver HIGH 7.8
CVE-2022-28184

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an …

Fix: 11.8 / 13.3+
Fix from $1,950 2022-05-17
Cmt Svr 100 Firmware CRITICAL 9.8
CVE-2021-27444

The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and do…

Fix: 20210209 / 20210222+
Fix from $2,300 2022-05-16
Publify MEDIUM 6.5
CVE-2022-0574

Improper Access Control in GitHub repository publify/publify prior to 9.2.8.

Fix: 9.2.8+
Fix from $1,600 2022-05-16
Sma 6200 Firmware CRITICAL 9.8
CVE-2022-22282EPSS 8%

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an…

Mitigation only
Fix from $2,300 2022-05-13
Mypro HIGH 7.5
CVE-2021-33013

mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.

Fix: 8.20.0+
Fix from $1,950 2022-05-13
Inrouter302 Firmware HIGH 8.8
CVE-2022-21182

A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-craft…

Fix: after 3.5.4
Fix from $1,950 2022-05-12
Windows 10 HIGH 7.8
CVE-2022-26926

Windows Address Book Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2022-05-10
Wpgraphql MEDIUM 5.3
CVE-2019-25060

The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of…

Fix: 0.3.5+
Fix from $1,600 2022-05-09
Microweber HIGH 8.8
CVE-2022-1631EPSS 9%

Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, th…

Fix: 1.2.15+
Fix from $1,950 2022-05-09
Enterprise Nfv Infrastructure Software CRITICAL 9.9
CVE-2022-20777EPSS 11%

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM…

Fix: 4.7.1+
Fix from $2,300 2022-05-04
Enterprise Nfv Infrastructure Software HIGH 8.8
CVE-2022-20779EPSS 10%

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM…

Fix: 4.7.1+
Fix from $1,950 2022-05-04
Enterprise Nfv Infrastructure Software HIGH 7.4
CVE-2022-20780EPSS 11%

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM…

Fix: 4.7.1+
Fix from $1,950 2022-05-04
Android MEDIUM 5.5
CVE-2022-28780

Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in We…

Mitigation only
Fix from $1,600 2022-05-03
Flo Launch CRITICAL 9.8
CVE-2022-0541

The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new sit…

Fix: 2.4.1+
Fix from $2,300 2022-04-25
Virtualized Infrastructure Manager HIGH 7.8
CVE-2022-20732

A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an authenticated, local attacker …

Fix: 4.2.2+
Fix from $1,950 2022-04-21
Roboguide HIGH 7.0
CVE-2021-43986

The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replac…

Fix: after 9.40083.00.05
Fix from $1,950 2022-04-20