Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Kubeoperator CRITICAL 9.8
CVE-2023-22480EPSS 67%

KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In Kube…

Fix: 3.16.4+
Fix from $2,300 2023-01-14
Windows 10 1607 HIGH 8.8
CVE-2023-21549

Windows SMB Witness Service Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2023-01-10
Royal Elementor Addons HIGH 8.8
CVE-2022-4701

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in ve…

Fix: after 1.3.59
Fix from $1,950 2023-01-10
Merlinsboard MEDIUM 6.5
CVE-2015-10033

A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of the component Grade Handler. …

Fix: 2015-03-19+
Fix from $1,600 2023-01-09
Forged Alliance Forever HIGH 7.5
CVE-2022-4879

A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown funct…

Fix: 3747+
Fix from $1,950 2023-01-06
Aslan Al10 Firmware MEDIUM 5.5
CVE-2022-45874

Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker to access certain file.

Fix: after 11.1.0.10118
Fix from $1,600 2022-12-28
Memos MEDIUM 5.3
CVE-2022-4804

Improper Authorization in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-28
Memos HIGH 8.8
CVE-2022-4688

Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.

Fix: 0.9.0+
Fix from $1,950 2022-12-23
Thunderbird MEDIUM 6.5
CVE-2022-29913

The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This v…

Fix: 91.9+
Fix from $1,600 2022-12-22
Iboot Pdu4 N20 Firmware MEDIUM 5.3
CVE-2022-3187

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is estab…

Fix: 1.42.06162022+
Fix from $1,600 2022-12-21
Harmonyos HIGH 7.5
CVE-2022-46312

The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected cle…

Fix: 2.1+
Fix from $1,950 2022-12-20
Openfga CRITICAL 9.8
CVE-2022-23542

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was di…

Fix: 0.3.1+
Fix from $2,300 2022-12-20
Transposh Wordpress Translation MEDIUM 5.3
CVE-2022-2536

The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, an…

Fix: after 1.0.8.1
Fix from $1,600 2022-12-15
Fp Newsletter HIGH 7.5
CVE-2022-47409

An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.…

Fix: 1.1.1 / 2.1.2+
Fix from $1,950 2022-12-14
Exynos Firmware HIGH 7.5
CVE-2022-39902

Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emer…

Mitigation only
Fix from $1,950 2022-12-08
Android MEDIUM 5.5
CVE-2022-39905

Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via im…

Mitigation only
Fix from $1,600 2022-12-08
Android HIGH 7.8
CVE-2022-39883

Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.

Mitigation only
Fix from $1,950 2022-11-09
Billing HIGH 7.5
CVE-2022-39890

Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.

Fix: 5.0.56.0+
Fix from $1,950 2022-11-09
Discourse HIGH 8.8
CVE-2022-39356

Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non…

Fix: 2.8.10+
Fix from $1,950 2022-11-02
Flx3 Cpuc1 Firmware CRITICAL 9.1
CVE-2022-27583

A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware…

Fix: 1.10.0+
Fix from $2,300 2022-10-31
Nextcloud Enterprise Server MEDIUM 5.3
CVE-2022-39329

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server pri…

Fix: 23.0.9 / 24.0.5+
Fix from $1,600 2022-10-27
Micollab HIGH 8.8
CVE-2022-36453

A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile pa…

Fix: after 9.5.0.101
Fix from $1,950 2022-10-25
Micollab MEDIUM 6.5
CVE-2022-36454

A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile paramete…

Fix: after 9.5.0.101
Fix from $1,600 2022-10-25
Keystone CRITICAL 9.8
CVE-2022-39322

@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, u…

Fix: 2.3.1+
Fix from $2,300 2022-10-25
Openfga MEDIUM 5.3
CVE-2022-39340

OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization head…

Fix: 0.2.4+
Fix from $1,600 2022-10-25
Openfga CRITICAL 9.8
CVE-2022-39341

OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users…

Fix: 0.2.4+
Fix from $2,300 2022-10-25
Openfga CRITICAL 9.8
CVE-2022-39342

OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users…

Fix: 0.2.4+
Fix from $2,300 2022-10-25
Wolfssl MEDIUM 5.3
CVE-2022-42961

An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signin…

Fix: 5.5.0+
Fix from $1,600 2022-10-15
Cloud Mobility For Dell Emc Storage MEDIUM 6.7
CVE-2022-34434

Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. A threat a…

Fix: 1.3.1+
Fix from $1,600 2022-10-11
Dynamic Lockscreen CRITICAL 9.8
CVE-2022-39862

Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use …

Fix: 3.3.03.66+
Fix from $2,300 2022-10-07