Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2022-28761 Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious act… Zoom On Premise Meeting Connector Mmr 4.8.20220916.131+ Fix from $1,6002022-10-14 HIGH 8.6 CVE-2022-28759 Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious act… Zoom On Premise Meeting Connector Mmr 4.8.20220815.130+ Fix from $1,9502022-10-14 HIGH 7.8 CVE-2022-42717 An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has bee… Vagrant 2.3.1+ Fix from $1,9502022-10-11 HIGH 7.5 CVE-2021-36913 Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows att… Redirection For Contact Form 7 2.6.0+ Fix from $1,9502022-10-11 MEDIUM 6.5 CVE-2022-34431 Dell Hybrid Client below 1.8 version contains a guest user profile corruption vulnerability. A WMS privilege attacker could potentially exploit this … Hybrid Client 1.8+ Fix from $1,6002022-10-11 MEDIUM 5.5 CVE-2022-38388 IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to improper access control. IBM X-F… Navigator Mobile Patch available Fix from $1,6002022-10-11 MEDIUM 5.3 CVE-2022-39877 Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(… Group Sharing 13.0.6.14 / 13.0.6.15+ Fix from $1,6002022-10-07 MEDIUM 5.5 CVE-2022-39878 Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via implicit int… Checkout 5.0.55.3+ Fix from $1,6002022-10-07 HIGH 7.5 CVE-2022-39867 Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf… Smartthings 1.7.89.0+ Fix from $1,9502022-10-07 HIGH 7.5 CVE-2022-39868 Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information … Smartthings 1.7.89.0+ Fix from $1,9502022-10-07 HIGH 7.5 CVE-2022-39869 Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf… Smartthings 1.7.89.0+ Fix from $1,9502022-10-07 HIGH 7.5 CVE-2022-39870 Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf… Smartthings 1.7.89.0+ Fix from $1,9502022-10-07 HIGH 7.5 CVE-2022-39871 Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf… Smartthings 1.7.89.0+ Fix from $1,9502022-10-07 HIGH 7.5 CVE-2022-39864 Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive informa… Smartthings 1.7.85.25+ Fix from $1,9502022-10-07 HIGH 7.5 CVE-2022-39865 Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive info… Smartthings 1.7.89.0+ Fix from $1,9502022-10-07 HIGH 7.5 CVE-2022-39866 Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inform… Smartthings 1.7.89.0+ Fix from $1,9502022-10-07 MEDIUM 5.5 CVE-2022-39857 Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent… Factorycamerafb 3.5.51+ Fix from $1,6002022-10-07 HIGH 7.8 CVE-2022-39854 Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory. Android Mitigation only Fix from $1,9502022-10-07 MEDIUM 6.6 CVE-2022-1959 AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is possible because the applica… Applock No fix yet Fix from $1,6002022-09-30 MEDIUM 6.5 CVE-2022-36771 IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-… Qradar User Behavior Analytics 4.1.9+ Fix from $1,6002022-09-28 MEDIUM 5.3 CVE-2022-39835 An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent b… Gajim 1.5.0+ Fix from $1,6002022-09-27 HIGH 7.8 CVE-2022-3263 The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileg… Scadapro Server Mitigation only Fix from $1,9502022-09-23 MEDIUM 5.5 CVE-2022-32848 A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to capture a u… macOS 11.6.8 / 12.5+ Fix from $1,6002022-09-23 MEDIUM 5.5 CVE-2022-32783 A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An app may gain unauthorized access to Bluetooth. macOS 12.4+ Fix from $1,6002022-09-23 MEDIUM 5.5 CVE-2022-32789 A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to bypass Privacy preferences. macOS 12.5+ Fix from $1,6002022-09-23 MEDIUM 5.5 CVE-2022-32800 This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. A… Mac Os X 10.15.7 / 11.6.8+ Fix from $1,6002022-09-23 MEDIUM 5.3 CVE-2022-35621 Access control vulnerability in Evoh NFT EvohClaimable contract with sha256 hash code fa2084d5abca91a62ed1d2f1cad3ec318e6a9a2d7f1510a00d898737b05f48a… Evohclaimable No fix yet Fix from $1,6002022-09-21 MEDIUM 5.3 CVE-2022-41235 Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins control… Wildfly Deployer after 1.0.2 Fix from $1,6002022-09-21 MEDIUM 6.5 CVE-2022-32880 This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to access user-sensitive data. macOS 12.5+ Fix from $1,6002022-09-20 MEDIUM 5.5 CVE-2022-32883 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 1… Ipados 9.0 / 11.7+ Fix from $1,6002022-09-20