Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Debian Linux HIGH 7.5
CVE-2022-21476

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Fix: after 17.0.2
Fix from $1,950 2022-04-19
Qcp200w Firmware HIGH 7.5
CVE-2021-26627

Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attac…

Mitigation only
Fix from $1,950 2022-04-19
Fleet HIGH 8.1
CVE-2022-24841

fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this autho…

Fix: 4.13+
Fix from $1,950 2022-04-18
WordPress MEDIUM 6.5
CVE-2011-1762

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow…

Fix: 3.0.6 / 3.1.2+
Fix from $1,600 2022-04-18
Catalyst Sd Wan Manager HIGH 7.8
CVE-2022-20716

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is …

Fix: 20.6.1 / 20.7.1+
Fix from $1,950 2022-04-15
Datamodule Compactplus MEDIUM 6.3
CVE-2020-25160

Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enab…

Mitigation only
Fix from $1,600 2022-04-14
Eos HIGH 7.5
CVE-2021-28505

On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the …

Fix: 4.26.4m / 4.27.1f+
Fix from $1,950 2022-04-14
Rlc 410w Firmware MEDIUM 6.5
CVE-2021-40405

A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted …

No fix yet
Fix from $1,600 2022-04-14
Paragon Active Assurance Control Center HIGH 7.5
CVE-2022-22190

An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to levera…

Mitigation only
Fix from $1,950 2022-04-14
Junos Os Evolved HIGH 7.5
CVE-2022-22183

An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect …

Mitigation only
Fix from $1,950 2022-04-14
Mendix MEDIUM 6.5
CVE-2022-25650

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications using Mendix 8 (All versions…

Fix: 7.23.27 / 8.18.14+
Fix from $1,600 2022-04-12
Scalance X302 7eec Firmware HIGH 7.5
CVE-2022-25755

A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC…

Fix: 4.1.4+
Fix from $1,950 2022-04-12
Simatic Step 7 HIGH 7.8
CVE-2021-42029

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5),…

Fix: 16+
Fix from $1,950 2022-04-12
Factorycamera HIGH 7.8
CVE-2022-27838

Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.

Fix: 2.1.96+
Fix from $1,950 2022-04-11
Galaxy Store MEDIUM 5.5
CVE-2022-28542

Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as G…

Fix: 4.5.40.5+
Fix from $1,600 2022-04-11
Android MEDIUM 5.5
CVE-2022-27822

Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.

Mitigation only
Fix from $1,600 2022-04-11
Android HIGH 7.8
CVE-2022-27836

Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local a…

Mitigation only
Fix from $1,950 2022-04-11
Android MEDIUM 6.8
CVE-2022-26091

Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a fu…

Mitigation only
Fix from $1,600 2022-04-11
Ultra Cloud Core Subscriber Microservices Infrastructure HIGH 7.8
CVE-2022-20762

A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure (SMI) softwar…

Fix: 2020.02.2.47 / 2020.02.7.07+
Fix from $1,950 2022-04-06
Rancher HIGH 8.8
CVE-2021-36775

a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Ranch…

Fix: 2.4.18 / 2.5.12+
Fix from $1,950 2022-04-04
Rancher HIGH 8.8
CVE-2021-36776

A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher…

Fix: 2.5.10+
Fix from $1,950 2022-04-04
Eos HIGH 7.5
CVE-2021-28504

On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol…

Fix: 4.26.4m / 4.27.1f+
Fix from $1,950 2022-04-01
Argo Cd MEDIUM 6.5
CVE-2022-24730

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and …

Fix: 2.1.11 / 2.2.6+
Fix from $1,600 2022-03-23
Thinkphp HIGH 7.5
CVE-2022-25481

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment par…

No fix yet
Fix from $1,950 2022-03-21
Webos CRITICAL 9.8
CVE-2022-23730

The public API error causes for the attacker to be able to bypass API access control.

No fix yet
Fix from $2,300 2022-03-11
Steelcentral Appinternals Dynamic Sampling Agent HIGH 7.8
CVE-2021-42855

It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that c…

Fix: 11.8.8 / 12.13.0+
Fix from $1,950 2022-03-10
Mendix HIGH 8.1
CVE-2022-24309

A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8.18.16), Mendix Runtime V9 (A…

Fix: 7.23.29 / 8.18.16+
Fix from $1,950 2022-03-08
Forgot Password CRITICAL 9.8
CVE-2022-26313

A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations of the aff…

Fix: 3.5.1+
Fix from $2,300 2022-03-08
Mendix MEDIUM 6.5
CVE-2022-26317

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the result of a completed Microfl…

Fix: 7.23.29+
Fix from $1,600 2022-03-08
Climatix Pol909 Firmware MEDIUM 6.5
CVE-2021-41543

A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). Th…

Fix: 11.36 / 11.44+
Fix from $1,600 2022-03-08