Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 8.8 CVE-2022-29490 Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execut… Microscada X Sys600 after 10.3.1 Fix from $1,9502022-09-12 HIGH 8.8 CVE-2022-36110 Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API… Netmaker 0.15.1+ Fix from $1,9502022-09-09 MEDIUM 6.5 CVE-2022-36870 Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows att… Samsung Pay 5.0.63 / 5.1.47+ Fix from $1,6002022-09-09 MEDIUM 6.5 CVE-2022-36871 Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to acc… Samsung Pay 5.0.63 / 5.1.47+ Fix from $1,6002022-09-09 MEDIUM 6.5 CVE-2022-36872 Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to ac… Samsung Pay 5.0.63 / 5.1.47+ Fix from $1,6002022-09-09 MEDIUM 5.5 CVE-2022-36848 Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of… Android Mitigation only Fix from $1,6002022-09-09 HIGH 8.1 CVE-2022-36090 XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14.3-rc-1, some resources are m… Xwiki 13.10.5+ Fix from $1,9502022-09-08 MEDIUM 6.5 CVE-2022-31167 XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.… Xwiki 12.10.11 / 13.4.6+ Fix from $1,6002022-09-07 CRITICAL 9.1 CVE-2022-31247 An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project… Rancher 2.5.16 / 2.6.7+ Fix from $2,3002022-09-07 HIGH 7.1 CVE-2022-2901 Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8. Chatwoot 2.8.0+ Fix from $1,9502022-09-06 HIGH 8.8 CVE-2022-20921 A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privile… Aci Multi Site Orchestrator 3.1+ Fix from $1,9502022-08-25 MEDIUM 5.5 CVE-2022-32838 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-00… Ipados 10.15.7 / 11.6.8+ Fix from $1,6002022-08-24 CRITICAL 9.8 CVE-2022-34256 Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerabilit… Commerce 2.3.7 / 2.4.3+ Fix from $2,3002022-08-16 HIGH 8.8 CVE-2022-2661 Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform administrative functions using speci… Portbloque S Firmware Mitigation only Fix from $1,9502022-08-16 HIGH 7.8 CVE-2022-31609 NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which … Virtual Gpu 11.8 / 13.3+ Fix from $1,9502022-08-05 MEDIUM 6.5 CVE-2022-2675 Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered d… Go 1 Firmware 0.1.35+ Fix from $1,6002022-08-05 MEDIUM 5.5 CVE-2022-36837 Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information. Samsung Email 6.1.70.20+ Fix from $1,6002022-08-05 CRITICAL 10.0 CVE-2022-2595 Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1. Titra 0.79.1+ Fix from $2,3002022-08-01 HIGH 8.8 CVE-2022-26310 Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management … Pandora Fms after 7.0_ng_760 Fix from $1,9502022-08-01 CRITICAL 9.8 CVE-2022-24083 Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. Infinity after 8.7.2 Fix from $2,3002022-07-25 HIGH 8.8 CVE-2022-31168 Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could cr… Zulip 5.5+ Fix from $1,9502022-07-22 MEDIUM 5.7 CVE-2022-2393 A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled.… Certificate System after 10.12.4 Fix from $1,6002022-07-14 MEDIUM 5.3 CVE-2022-33712 Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S… Camera 12.0.0.98 / 12.0.01.64+ Fix from $1,6002022-07-12 HIGH 7.5 CVE-2022-33713 Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information. Cloud 5.2.0+ Fix from $1,9502022-07-12 MEDIUM 5.5 CVE-2022-33702 Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock… Android Mitigation only Fix from $1,6002022-07-12 HIGH 8.8 CVE-2022-30670 RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalatio… Robohelp Server 11+ Fix from $1,9502022-06-16 HIGH 7.5 CVE-2022-2019 A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulnerability is an unknown functio… Prison Management System No fix yet Fix from $1,9502022-06-09 HIGH 7.5 CVE-2022-30746 Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface AP… Smartthings 1.7.85.12+ Fix from $1,9502022-06-07 HIGH 7.5 CVE-2022-30717 Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink. Android Mitigation only Fix from $1,9502022-06-07 CRITICAL 9.8 CVE-2022-30722 Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Ac… Android Mitigation only Fix from $2,3002022-06-07