Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Discourse MEDIUM 5.3
CVE-2022-31025

Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-…

Fix: 2.8.4+
Fix from $1,600 2022-06-07
Itunes HIGH 7.1
CVE-2022-26773

A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. An application may be able to delete f…

Fix: 12.12.4+
Fix from $1,950 2022-05-26
Openmanage Enterprise HIGH 8.8
CVE-2022-26857

Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low p…

Fix: 3.8.4+
Fix from $1,950 2022-05-26
Sametime MEDIUM 6.5
CVE-2021-27772

Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conv…

Mitigation only
Fix from $1,600 2022-05-12
Smartptt Scada HIGH 8.8
CVE-2021-43939

Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by issuing requests directly to t…

Mitigation only
Fix from $1,950 2022-04-28
Siteground Security CRITICAL 9.8
CVE-2022-0993EPSS 7%

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative use…

Fix: after 1.2.5
Fix from $2,300 2022-04-19
Galaxy Store HIGH 7.8
CVE-2022-28776

Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without use…

Fix: 4.5.36.4+
Fix from $1,950 2022-04-11
Phpipam MEDIUM 6.5
CVE-2022-1224

Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

Fix: 1.4.6+
Fix from $1,600 2022-04-04
Fedora CRITICAL 9.1
CVE-2022-0860

Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

Fix: 3.3.2+
Fix from $2,300 2022-03-11
Orchardcore MEDIUM 6.5
CVE-2022-0821

Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

Fix: 1.3.0+
Fix from $1,600 2022-03-11
Webmin HIGH 8.1
CVE-2022-0829

Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

Fix: 1.990+
Fix from $1,950 2022-03-02
Mimosa Management Platform CRITICAL 9.8
CVE-2022-21196

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does…

Fix: 1.0.3 / 2.5.4.1+
Fix from $2,300 2022-02-18
Librenms MEDIUM 6.5
CVE-2022-0587

Improper Authorization in Packagist librenms/librenms prior to 22.2.0.

Fix: 22.2.0+
Fix from $1,600 2022-02-15
Link Sharing MEDIUM 5.3
CVE-2022-24002

Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.

Fix: 12.4.00.3+
Fix from $1,600 2022-02-11
Pingfederate MEDIUM 6.5
CVE-2021-42000

When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports mult…

Fix: after 10.3.2
Fix from $1,600 2022-02-10
True Image HIGH 7.8
CVE-2021-44204

Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windo…

Mitigation only
Fix from $1,950 2022-02-04
Eos HIGH 7.8
CVE-2021-28500

An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result i…

Fix: 4.20+
Fix from $1,950 2022-01-14
Terminattr HIGH 7.8
CVE-2021-28501

An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result i…

Fix: after 1.16.2
Fix from $1,950 2022-01-14
Eos CRITICAL 9.1
CVE-2021-28506

An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially…

Fix: after 4.26.2f
Fix from $2,300 2022-01-14
Galaxy Store HIGH 7.5
CVE-2022-22288

Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.

Fix: 4.5.36.5+
Fix from $1,950 2022-01-10
Android MEDIUM 6.1
CVE-2022-22268

Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via S…

Mitigation only
Fix from $1,600 2022-01-10
Zw090 A MEDIUM 6.5
CVE-2020-9061

Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version …

Mitigation only
Fix from $1,600 2022-01-10
Openwhyd MEDIUM 6.1
CVE-2021-3837

openwhyd is vulnerable to Improper Authorization

Fix: 1.45.12+
Fix from $1,600 2022-01-03
Humhub MEDIUM 6.5
CVE-2021-43847

HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to bec…

Fix: 1.9.3 / 1.10.3+
Fix from $1,600 2021-12-20
Avalanche HIGH 8.8
CVE-2021-42126

An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to per…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Emc Networker HIGH 7.8
CVE-2021-36311

Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privileges ma…

Fix: 19.5.0.0+
Fix from $1,950 2021-11-23
Gcb Doctor CRITICAL 9.8
CVE-2021-42338EPSS 6%

4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code in…

Fix: after 20210708
Fix from $2,300 2021-11-19
Samsung Flow MEDIUM 5.7
CVE-2021-25507

Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user devi…

Fix: 4.8.03.5+
Fix from $1,600 2021-11-05
Publify MEDIUM 6.5
CVE-2021-25973

In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. T…

Fix: after 9.2.4
Fix from $1,600 2021-11-02
Optinmonster HIGH 8.2
CVE-2021-39341EPSS 22%

The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorizatio…

Fix: after 2.6.4
Fix from $1,950 2021-11-01