Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 5.3 CVE-2022-31025 Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-… Discourse 2.8.4+ Fix from $1,6002022-06-07 HIGH 7.1 CVE-2022-26773 A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. An application may be able to delete f… Itunes 12.12.4+ Fix from $1,9502022-05-26 HIGH 8.8 CVE-2022-26857 Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low p… Openmanage Enterprise 3.8.4+ Fix from $1,9502022-05-26 MEDIUM 6.5 CVE-2021-27772 Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conv… Sametime Mitigation only Fix from $1,6002022-05-12 HIGH 8.8 CVE-2021-43939 Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by issuing requests directly to t… Smartptt Scada Mitigation only Fix from $1,9502022-04-28 CRITICAL 9.8 CVE-2022-0993EPSS 7% The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative use… Siteground Security after 1.2.5 Fix from $2,3002022-04-19 HIGH 7.8 CVE-2022-28776 Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without use… Galaxy Store 4.5.36.4+ Fix from $1,9502022-04-11 MEDIUM 6.5 CVE-2022-1224 Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. Phpipam 1.4.6+ Fix from $1,6002022-04-04 CRITICAL 9.1 CVE-2022-0860 Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2. Fedora 3.3.2+ Fix from $2,3002022-03-11 MEDIUM 6.5 CVE-2022-0821 Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0. Orchardcore 1.3.0+ Fix from $1,6002022-03-11 HIGH 8.1 CVE-2022-0829 Improper Authorization in GitHub repository webmin/webmin prior to 1.990. Webmin 1.990+ Fix from $1,9502022-03-02 CRITICAL 9.8 CVE-2022-21196 MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does… Mimosa Management Platform 1.0.3 / 2.5.4.1+ Fix from $2,3002022-02-18 MEDIUM 6.5 CVE-2022-0587 Improper Authorization in Packagist librenms/librenms prior to 22.2.0. Librenms 22.2.0+ Fix from $1,6002022-02-15 MEDIUM 5.3 CVE-2022-24002 Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity. Link Sharing 12.4.00.3+ Fix from $1,6002022-02-11 MEDIUM 6.5 CVE-2021-42000 When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports mult… Pingfederate after 10.3.2 Fix from $1,6002022-02-10 HIGH 7.8 CVE-2021-44204 Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windo… True Image Mitigation only Fix from $1,9502022-02-04 HIGH 7.8 CVE-2021-28500 An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result i… Eos 4.20+ Fix from $1,9502022-01-14 HIGH 7.8 CVE-2021-28501 An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result i… Terminattr after 1.16.2 Fix from $1,9502022-01-14 CRITICAL 9.1 CVE-2021-28506 An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially… Eos after 4.26.2f Fix from $2,3002022-01-14 HIGH 7.5 CVE-2022-22288 Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist. Galaxy Store 4.5.36.5+ Fix from $1,9502022-01-10 MEDIUM 6.1 CVE-2022-22268 Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via S… Android Mitigation only Fix from $1,6002022-01-10 MEDIUM 6.5 CVE-2020-9061 Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version … Zw090 A Mitigation only Fix from $1,6002022-01-10 MEDIUM 6.1 CVE-2021-3837 openwhyd is vulnerable to Improper Authorization Openwhyd 1.45.12+ Fix from $1,6002022-01-03 MEDIUM 6.5 CVE-2021-43847 HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to bec… Humhub 1.9.3 / 1.10.3+ Fix from $1,6002021-12-20 HIGH 8.8 CVE-2021-42126 An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to per… Avalanche 6.3.3+ Fix from $1,9502021-12-07 HIGH 7.8 CVE-2021-36311 Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privileges ma… Emc Networker 19.5.0.0+ Fix from $1,9502021-11-23 CRITICAL 9.8 CVE-2021-42338EPSS 6% 4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code in… Gcb Doctor after 20210708 Fix from $2,3002021-11-19 MEDIUM 5.7 CVE-2021-25507 Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user devi… Samsung Flow 4.8.03.5+ Fix from $1,6002021-11-05 MEDIUM 6.5 CVE-2021-25973 In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. T… Publify after 9.2.4 Fix from $1,6002021-11-02 HIGH 8.2 CVE-2021-39341EPSS 22% The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorizatio… Optinmonster after 2.6.4 Fix from $1,9502021-11-01