Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.5 CVE-2022-32946 This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair o… Ipados 16.0 / 16.1+ Fix from $1,6002022-11-01 MEDIUM 5.5 CVE-2022-32904 An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6.… macOS 11.7 / 12.6+ Fix from $1,6002022-11-01 MEDIUM 5.5 CVE-2022-32918 This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to bypass Privacy prefere… Iphone Os 13.0 / 16.0+ Fix from $1,6002022-11-01 HIGH 7.5 CVE-2022-3780 Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users … Remote Desktop Manager 2022.3.8+ Fix from $1,9502022-11-01 HIGH 7.1 CVE-2022-42327 x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the gl… Fedora Patch available Fix from $1,9502022-11-01 MEDIUM 5.3 CVE-2022-39329 Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server pri… Nextcloud Enterprise Server 23.0.9 / 24.0.5+ Fix from $1,6002022-10-27 MEDIUM 6.5 CVE-2022-33757 An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead … Nessus 10.2.0+ Fix from $1,6002022-10-25 CRITICAL 9.8 CVE-2022-27805 An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A… Iota All In One Security Kit Firmware Mitigation only Fix from $2,3002022-10-25 HIGH 7.5 CVE-2021-44467 A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrarily terminate active sessions … Iac Ast2500a Firmware Mitigation only Fix from $1,9502022-10-24 MEDIUM 5.3 CVE-2021-44776 A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbitrarily change the security ac… Iac Ast2500a Firmware Mitigation only Fix from $1,6002022-10-24 MEDIUM 5.3 CVE-2021-26732 A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network conf… Iac Ast2500a Firmware Mitigation only Fix from $1,6002022-10-24 HIGH 7.5 CVE-2021-26733 A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot comman… Iac Ast2500a Firmware Mitigation only Fix from $1,9502022-10-24 HIGH 8.2 CVE-2022-1066 Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials. Tug Home Base Server 24+ Fix from $1,9502022-10-21 HIGH 7.5 CVE-2022-26423 Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials. Tug Home Base Server 24+ Fix from $1,9502022-10-21 HIGH 8.1 CVE-2022-23241 Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an aut… Clustered Data Ontap Mitigation only Fix from $1,9502022-10-19 HIGH 7.5 CVE-2022-43429 Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, … Compuware Topaz For Total Test after 2.4.8 Fix from $1,9502022-10-19 HIGH 7.5 CVE-2022-40798 OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct … Ocomon 4.0+ Fix from $1,9502022-10-19 MEDIUM 5.3 CVE-2022-39405 Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The supported version that is affe… Access Manager Patch available Fix from $1,6002022-10-18 HIGH 8.1 CVE-2022-39406 Vulnerability in the PeopleSoft Enterprise Common Components product of Oracle PeopleSoft (component: Approval Framework). The supported version that… Peoplesoft Enterprise Common Components Patch available Fix from $1,9502022-10-18 HIGH 7.3 CVE-2022-39421 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4… Vm Virtualbox 6.1.40+ Fix from $1,9502022-10-18 HIGH 8.1 CVE-2020-8973 ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed requests. This allows an attacke… Zgr Tps200 Ng Firmware Mitigation only Fix from $1,9502022-10-17 HIGH 8.8 CVE-2022-38743 Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The Fac… Factorytalk Vantagepoint Mitigation only Fix from $1,9502022-10-17 HIGH 7.5 CVE-2022-3382 HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an attacker could craft code to… Robot System Software Mitigation only Fix from $1,9502022-10-17 MEDIUM 5.4 CVE-2022-3066 An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all ve… GitLab 15.2.5 / 15.3.4+ Fix from $1,6002022-10-17 MEDIUM 6.5 CVE-2022-3067 An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starti… GitLab 15.2.5 / 15.3.4+ Fix from $1,6002022-10-17 MEDIUM 5.3 CVE-2022-3286 Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a gr… GitLab 15.2.5 / 15.3.4+ Fix from $1,6002022-10-17 CRITICAL 9.8 CVE-2022-2052 Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gai… Job Order Interface after 1.6 Fix from $2,3002022-10-17 MEDIUM 6.5 CVE-2022-39310 GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go… Gocd 21.1.0+ Fix from $1,6002022-10-14 MEDIUM 5.3 CVE-2022-35689 Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in … Commerce 2.4.4+ Fix from $1,6002022-10-14 MEDIUM 6.5 CVE-2022-28760 Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious act… Zoom On Premise Meeting Connector Mmr 4.8.20220815.130+ Fix from $1,6002022-10-14