Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Microscada X Sys600 HIGH 8.8
CVE-2022-29490

Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execut…

Fix: after 10.3.1
Fix from $1,950 2022-09-12
Netmaker HIGH 8.8
CVE-2022-36110

Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API…

Fix: 0.15.1+
Fix from $1,950 2022-09-09
Samsung Pay MEDIUM 6.5
CVE-2022-36870

Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows att…

Fix: 5.0.63 / 5.1.47+
Fix from $1,600 2022-09-09
Samsung Pay MEDIUM 6.5
CVE-2022-36871

Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to acc…

Fix: 5.0.63 / 5.1.47+
Fix from $1,600 2022-09-09
Samsung Pay MEDIUM 6.5
CVE-2022-36872

Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to ac…

Fix: 5.0.63 / 5.1.47+
Fix from $1,600 2022-09-09
Android MEDIUM 5.5
CVE-2022-36848

Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of…

Mitigation only
Fix from $1,600 2022-09-09
Xwiki HIGH 8.1
CVE-2022-36090

XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14.3-rc-1, some resources are m…

Fix: 13.10.5+
Fix from $1,950 2022-09-08
Xwiki MEDIUM 6.5
CVE-2022-31167

XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.…

Fix: 12.10.11 / 13.4.6+
Fix from $1,600 2022-09-07
Rancher CRITICAL 9.1
CVE-2022-31247

An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project…

Fix: 2.5.16 / 2.6.7+
Fix from $2,300 2022-09-07
Chatwoot HIGH 7.1
CVE-2022-2901

Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.

Fix: 2.8.0+
Fix from $1,950 2022-09-06
Aci Multi Site Orchestrator HIGH 8.8
CVE-2022-20921

A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privile…

Fix: 3.1+
Fix from $1,950 2022-08-25
Ipados MEDIUM 5.5
CVE-2022-32838

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-00…

Fix: 10.15.7 / 11.6.8+
Fix from $1,600 2022-08-24
Commerce CRITICAL 9.8
CVE-2022-34256

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerabilit…

Fix: 2.3.7 / 2.4.3+
Fix from $2,300 2022-08-16
Portbloque S Firmware HIGH 8.8
CVE-2022-2661

Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform administrative functions using speci…

Mitigation only
Fix from $1,950 2022-08-16
Virtual Gpu HIGH 7.8
CVE-2022-31609

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which …

Fix: 11.8 / 13.3+
Fix from $1,950 2022-08-05
Go 1 Firmware MEDIUM 6.5
CVE-2022-2675

Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered d…

Fix: 0.1.35+
Fix from $1,600 2022-08-05
Samsung Email MEDIUM 5.5
CVE-2022-36837

Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.

Fix: 6.1.70.20+
Fix from $1,600 2022-08-05
Titra CRITICAL 10.0
CVE-2022-2595

Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.

Fix: 0.79.1+
Fix from $2,300 2022-08-01
Pandora Fms HIGH 8.8
CVE-2022-26310

Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management …

Fix: after 7.0_ng_760
Fix from $1,950 2022-08-01
Infinity CRITICAL 9.8
CVE-2022-24083

Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

Fix: after 8.7.2
Fix from $2,300 2022-07-25
Zulip HIGH 8.8
CVE-2022-31168

Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could cr…

Fix: 5.5+
Fix from $1,950 2022-07-22
Certificate System MEDIUM 5.7
CVE-2022-2393

A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled.…

Fix: after 10.12.4
Fix from $1,600 2022-07-14
Camera MEDIUM 5.3
CVE-2022-33712

Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S…

Fix: 12.0.0.98 / 12.0.01.64+
Fix from $1,600 2022-07-12
Cloud HIGH 7.5
CVE-2022-33713

Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information.

Fix: 5.2.0+
Fix from $1,950 2022-07-12
Android MEDIUM 5.5
CVE-2022-33702

Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock…

Mitigation only
Fix from $1,600 2022-07-12
Robohelp Server HIGH 8.8
CVE-2022-30670

RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalatio…

Fix: 11+
Fix from $1,950 2022-06-16
Prison Management System HIGH 7.5
CVE-2022-2019

A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulnerability is an unknown functio…

No fix yet
Fix from $1,950 2022-06-09
Smartthings HIGH 7.5
CVE-2022-30746

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface AP…

Fix: 1.7.85.12+
Fix from $1,950 2022-06-07
Android HIGH 7.5
CVE-2022-30717

Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.

Mitigation only
Fix from $1,950 2022-06-07
Android CRITICAL 9.8
CVE-2022-30722

Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Ac…

Mitigation only
Fix from $2,300 2022-06-07