Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 10.0 CVE-2022-32158 Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients t… Splunk 9.0+ Fix from $2,3002022-06-15 MEDIUM 6.5 CVE-2022-1958 A vulnerability classified as critical has been found in FileCloud. Affected is an unknown function of the component NTFS Handler. The manipulation l… Filecloud 21.3.5.18513+ Fix from $1,6002022-06-15 MEDIUM 5.3 CVE-2022-32255 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that la… Sinema Remote Connect Server 3.1+ Fix from $1,6002022-06-14 MEDIUM 6.5 CVE-2022-32256 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that la… Sinema Remote Connect Server 3.1+ Fix from $1,6002022-06-14 HIGH 7.5 CVE-2022-31055 kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was bro… Kctf 1.6.0+ Fix from $1,9502022-06-13 MEDIUM 5.4 CVE-2022-1658 Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber r… Jupiter after 6.10.1 Fix from $1,6002022-06-13 HIGH 7.3 CVE-2022-1659 Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which can be used to call any functio… Jupiterx after 2.0.6 Fix from $1,9502022-06-13 MEDIUM 5.4 CVE-2022-1656 Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions regist… Jupiter X Core after 2.0.6 Fix from $1,6002022-06-13 MEDIUM 5.5 CVE-2022-30745 Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share. Quick Share 13.1.2.4+ Fix from $1,6002022-06-07 MEDIUM 5.3 CVE-2022-30715 Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window. Android Mitigation only Fix from $1,6002022-06-07 MEDIUM 6.5 CVE-2022-31024 richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user… Richdocuments 4.2.6 / 5.0.4+ Fix from $1,6002022-06-02 HIGH 8.8 CVE-2022-1261 Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to … Matrikon Opc Server Mitigation only Fix from $1,9502022-05-26 MEDIUM 6.5 CVE-2021-41834 JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged… Artifactory 6.23.38 / 7.28.0+ Fix from $1,6002022-05-23 HIGH 7.8 CVE-2020-4107 HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this … Domino Mitigation only Fix from $1,9502022-05-19 HIGH 7.8 CVE-2022-28184 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an … Gpu Display Driver 11.8 / 13.3+ Fix from $1,9502022-05-17 CRITICAL 9.8 CVE-2021-27444 The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and do… Cmt Svr 100 Firmware 20210209 / 20210222+ Fix from $2,3002022-05-16 MEDIUM 6.5 CVE-2022-0574 Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Publify 9.2.8+ Fix from $1,6002022-05-16 CRITICAL 9.8 CVE-2022-22282EPSS 8% SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an… Sma 6200 Firmware Mitigation only Fix from $2,3002022-05-13 HIGH 7.5 CVE-2021-33013 mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information. Mypro 8.20.0+ Fix from $1,9502022-05-13 HIGH 8.8 CVE-2022-21182 A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-craft… Inrouter302 Firmware after 3.5.4 Fix from $1,9502022-05-12 HIGH 7.8 CVE-2022-26926 Windows Address Book Remote Code Execution Vulnerability Windows 10 Patch available Fix from $1,9502022-05-10 MEDIUM 5.3 CVE-2019-25060 The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of… Wpgraphql 0.3.5+ Fix from $1,6002022-05-09 HIGH 8.8 CVE-2022-1631EPSS 9% Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, th… Microweber 1.2.15+ Fix from $1,9502022-05-09 CRITICAL 9.9 CVE-2022-20777EPSS 11% Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM… Enterprise Nfv Infrastructure Software 4.7.1+ Fix from $2,3002022-05-04 HIGH 8.8 CVE-2022-20779EPSS 10% Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM… Enterprise Nfv Infrastructure Software 4.7.1+ Fix from $1,9502022-05-04 HIGH 7.4 CVE-2022-20780EPSS 11% Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM… Enterprise Nfv Infrastructure Software 4.7.1+ Fix from $1,9502022-05-04 MEDIUM 5.5 CVE-2022-28780 Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in We… Android Mitigation only Fix from $1,6002022-05-03 CRITICAL 9.8 CVE-2022-0541 The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new sit… Flo Launch 2.4.1+ Fix from $2,3002022-04-25 HIGH 7.8 CVE-2022-20732 A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an authenticated, local attacker … Virtualized Infrastructure Manager 4.2.2+ Fix from $1,9502022-04-21 HIGH 7.0 CVE-2021-43986 The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replac… Roboguide after 9.40083.00.05 Fix from $1,9502022-04-20