Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
CRITICAL 9.8 CVE-2023-22480EPSS 67% KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In Kube… Kubeoperator 3.16.4+ Fix from $2,3002023-01-14 HIGH 8.8 CVE-2023-21549 Windows SMB Witness Service Elevation of Privilege Vulnerability Windows 10 1607 Mitigation only Fix from $1,9502023-01-10 HIGH 8.8 CVE-2022-4701 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in ve… Royal Elementor Addons after 1.3.59 Fix from $1,9502023-01-10 MEDIUM 6.5 CVE-2015-10033 A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of the component Grade Handler. … Merlinsboard 2015-03-19+ Fix from $1,6002023-01-09 HIGH 7.5 CVE-2022-4879 A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown funct… Forged Alliance Forever 3747+ Fix from $1,9502023-01-06 MEDIUM 5.5 CVE-2022-45874 Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker to access certain file. Aslan Al10 Firmware after 11.1.0.10118 Fix from $1,6002022-12-28 MEDIUM 5.3 CVE-2022-4804 Improper Authorization in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-28 HIGH 8.8 CVE-2022-4688 Improper Authorization in GitHub repository usememos/memos prior to 0.9.0. Memos 0.9.0+ Fix from $1,9502022-12-23 MEDIUM 6.5 CVE-2022-29913 The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This v… Thunderbird 91.9+ Fix from $1,6002022-12-22 MEDIUM 5.3 CVE-2022-3187 Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is estab… Iboot Pdu4 N20 Firmware 1.42.06162022+ Fix from $1,6002022-12-21 HIGH 7.5 CVE-2022-46312 The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected cle… Harmonyos 2.1+ Fix from $1,9502022-12-20 CRITICAL 9.8 CVE-2022-23542 OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was di… Openfga 0.3.1+ Fix from $2,3002022-12-20 MEDIUM 5.3 CVE-2022-2536 The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, an… Transposh Wordpress Translation after 1.0.8.1 Fix from $1,6002022-12-15 HIGH 7.5 CVE-2022-47409 An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.… Fp Newsletter 1.1.1 / 2.1.2+ Fix from $1,9502022-12-14 HIGH 7.5 CVE-2022-39902 Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emer… Exynos Firmware Mitigation only Fix from $1,9502022-12-08 MEDIUM 5.5 CVE-2022-39905 Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via im… Android Mitigation only Fix from $1,6002022-12-08 HIGH 7.8 CVE-2022-39883 Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API. Android Mitigation only Fix from $1,9502022-11-09 HIGH 7.5 CVE-2022-39890 Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information. Billing 5.0.56.0+ Fix from $1,9502022-11-09 HIGH 8.8 CVE-2022-39356 Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non… Discourse 2.8.10+ Fix from $1,9502022-11-02 CRITICAL 9.1 CVE-2022-27583 A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware… Flx3 Cpuc1 Firmware 1.10.0+ Fix from $2,3002022-10-31 MEDIUM 5.3 CVE-2022-39329 Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server pri… Nextcloud Enterprise Server 23.0.9 / 24.0.5+ Fix from $1,6002022-10-27 HIGH 8.8 CVE-2022-36453 A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile pa… Micollab after 9.5.0.101 Fix from $1,9502022-10-25 MEDIUM 6.5 CVE-2022-36454 A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile paramete… Micollab after 9.5.0.101 Fix from $1,6002022-10-25 CRITICAL 9.8 CVE-2022-39322 @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, u… Keystone 2.3.1+ Fix from $2,3002022-10-25 MEDIUM 5.3 CVE-2022-39340 OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization head… Openfga 0.2.4+ Fix from $1,6002022-10-25 CRITICAL 9.8 CVE-2022-39341 OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users… Openfga 0.2.4+ Fix from $2,3002022-10-25 CRITICAL 9.8 CVE-2022-39342 OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users… Openfga 0.2.4+ Fix from $2,3002022-10-25 MEDIUM 5.3 CVE-2022-42961 An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signin… Wolfssl 5.5.0+ Fix from $1,6002022-10-15 MEDIUM 6.7 CVE-2022-34434 Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. A threat a… Cloud Mobility For Dell Emc Storage 1.3.1+ Fix from $1,6002022-10-11 CRITICAL 9.8 CVE-2022-39862 Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use … Dynamic Lockscreen 3.3.03.66+ Fix from $2,3002022-10-07