Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2022-0143 When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connecto… Ldap Connector 1.5.20.9+ Fix from $2,3002022-09-19 CRITICAL 9.8 CVE-2022-23768 This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all… Nis Hap11ac Firmware Mitigation only Fix from $2,3002022-09-19 HIGH 7.1 CVE-2022-2995 Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modifica… Cri O Patch available Fix from $1,9502022-09-19 HIGH 8.2 CVE-2022-28758 Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious act… Zoom On Premise Meeting Connector Mmr 4.8.20220815.130+ Fix from $1,9502022-09-16 HIGH 7.0 CVE-2022-3182 Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypas… Remote Desktop Manager 2022.2.15+ Fix from $1,9502022-09-13 MEDIUM 5.7 CVE-2022-3027 The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malici… Cms8000 Firmware Mitigation only Fix from $1,6002022-09-13 MEDIUM 6.8 CVE-2022-36385 A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to… Cms8000 Firmware Mitigation only Fix from $1,6002022-09-13 HIGH 7.8 CVE-2022-38466 A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file p… Coreshield One Way Gateway 2.2+ Fix from $1,9502022-09-13 MEDIUM 5.5 CVE-2022-36875 Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the f… Galaxy Watch Plugin 2.2.11.22081151+ Fix from $1,6002022-09-09 HIGH 7.8 CVE-2022-36864 Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute priv… Samsung Email 6.1.70.20+ Fix from $1,9502022-09-09 MEDIUM 5.5 CVE-2022-36867 Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information. Editor Lite 4.0.40.14+ Fix from $1,6002022-09-09 MEDIUM 6.1 CVE-2022-36869 Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file withou… Contacts Provider 12.7.59+ Fix from $1,6002022-09-09 HIGH 8.8 CVE-2022-20696 A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has ac… Catalyst Sd Wan Manager 20.6.4 / 20.9.1+ Fix from $1,9502022-09-08 MEDIUM 5.5 CVE-2022-36088 GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately rest… Gocd 22.2.0+ Fix from $1,6002022-09-07 MEDIUM 5.3 CVE-2022-21950 A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local u… Canna 3.7p3-bp153.2.3.1 / 3.7p3-bp154.3.3.1+ Fix from $1,6002022-09-07 HIGH 7.5 CVE-2022-3065 Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8. Drawio 20.2.8+ Fix from $1,9502022-09-02 HIGH 8.8 CVE-2022-3019 The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comme… Tooljet 1.23.0+ Fix from $1,9502022-08-29 HIGH 7.0 CVE-2021-3864 A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID bin… Linux Kernel Patch available Fix from $1,9502022-08-26 MEDIUM 5.5 CVE-2022-32834 An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 202… Mac Os X 10.15.7 / 11.6.8+ Fix from $1,6002022-08-24 HIGH 7.8 CVE-2021-4037 A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS… Linux Kernel 5.11+ Fix from $1,9502022-08-24 HIGH 7.5 CVE-2022-2792 Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a dire… Electric\'s Proficy after 9.0.0 Fix from $1,9502022-08-19 HIGH 7.3 CVE-2022-36263 StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .e… Streamlabs Desktop No fix yet Fix from $1,9502022-08-19 MEDIUM 6.5 CVE-2022-36024 py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to remote shutdown if they are ad… Pycord Patch available Fix from $1,6002022-08-18 HIGH 8.8 CVE-2022-34255 Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerabili… Commerce 2.3.7 / 2.4.3+ Fix from $1,9502022-08-16 MEDIUM 5.3 CVE-2022-34259 Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerabili… Commerce 2.3.7 / 2.4.3+ Fix from $1,6002022-08-16 HIGH 7.8 CVE-2022-37393 Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended function… Collaboration Patch available Fix from $1,9502022-08-16 HIGH 7.5 CVE-2022-38184 There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker… Portal For Arcgis after 10.8.1 Fix from $1,9502022-08-16 MEDIUM 5.4 CVE-2022-28753 Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious act… Meeting Connector 4.8.129.20220714+ Fix from $1,6002022-08-11 MEDIUM 5.4 CVE-2022-28754 Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious act… Meeting Connector 4.8.129.20220714+ Fix from $1,6002022-08-11 HIGH 7.5 CVE-2022-36923EPSS 7% Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 20… Manageengine Firewall Analyzer Mitigation only Fix from $1,9502022-08-10