Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-35843
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 thr…
Fortiproxy
after 7.0.7
HIGH 7.4
CVE-2022-44211
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.
Goodcloud
after 1.0
MEDIUM 5.9
CVE-2022-44212
In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.
Goodcloud
after 1.0
MEDIUM 5.3
CVE-2022-41970
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through …
Nextcloud Server
24.0.7+
CRITICAL 9.8
CVE-2022-4229
A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability affects unknown code of the f…
Book Store Management System
No fix yet
HIGH 8.8
CVE-2022-44037
An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allows attacke…
Ecu C Firmware
No fix yet
MEDIUM 6.5
CVE-2022-45475
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the ap…
Tiny File Manager
No fix yet
CRITICAL 9.8
CVE-2022-39070
There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulner…
Zxa10 C350m Firmware
2.1.0xgp002.4+
CRITICAL 9.8
CVE-2022-41155
Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.
Iq Block Country
1.2.19+
MEDIUM 5.3
CVE-2022-41135
Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.
Customizable Wordpress Gallery Plugin Modula Image Gallery
2.6.91+
MEDIUM 6.5
CVE-2022-40216
Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.
Better Messages
1.9.10.71+
CRITICAL 9.9
CVE-2022-34827
Carel Boss Mini 1.5.0 has Improper Access Control.
Boss Mini Firmware
No fix yet
CRITICAL 9.8
CVE-2022-41652
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
Quiz And Survey Master
7.3.11+
MEDIUM 6.5
CVE-2022-24038
Karmasis Informatics Infraskope SIEM+
has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page w…
Infraskope Siem\+
7.10.00+
HIGH 8.6
CVE-2022-24036
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs.
Infraskope Siem\+
7.10.00+
HIGH 7.5
CVE-2022-20918
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) F…
Firepower Services Software For Asa
7.0.5+
MEDIUM 5.5
CVE-2022-25679
Denial of service in video due to improper access control in broadcast receivers in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industria…
Aqt1000 Firmware
Mitigation only
HIGH 7.8
CVE-2022-36789
Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML357.0…
Nuc 10 Performance Kit Nuc10i7fnhn Firmware
Mitigation only
MEDIUM 6.7
CVE-2022-35276
Improper access control in BIOS firmware for some Intel(R) NUC 8 Compute Elements before version CBWHL357.0096 may allow a privileged user to potenti…
Nuc 8 Compute Element Cm8i7cb Firmware
Patch available
MEDIUM 5.3
CVE-2022-43679
The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused t…
Owncloud
after 10.11.0
CRITICAL 9.8
CVE-2022-31687
VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Ass…
Workspace One Assist
22.10+
HIGH 7.5
CVE-2022-27673
Insufficient access controls in the AMD Link Android app may potentially result in information disclosure.
Amd Link
5.0.220614+
CRITICAL 9.8
CVE-2021-46851
The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video …
Emui
No fix yet
HIGH 7.8
CVE-2021-26360
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow …
Enterprise Driver
22.q2 / 22.5.2+
CRITICAL 9.8
CVE-2022-25932
The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker c…
Inrouter302 Firmware
3.5.56+
HIGH 7.5
CVE-2022-42707
In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a suffic…
Mahara
21.04.7 / 21.10.5+
MEDIUM 6.5
CVE-2022-22442
"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to i…
Infosphere Information Server
Patch available
MEDIUM 5.3
CVE-2022-44622
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
Teamcity
2022.10+
MEDIUM 5.5
CVE-2022-42811
An access issue was addressed with additional sandbox restrictions. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watch…
Ipados
9.1 / 13.0+
MEDIUM 5.5
CVE-2022-42814
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.
macOS
13.0+