Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2022-48242

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution priv…

Mitigation only
Fix from $1,600 2023-05-09
Android HIGH 7.8
CVE-2022-48243

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

Mitigation only
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-48244

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

Mitigation only
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-48245

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

Mitigation only
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-48246

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

Mitigation only
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-48247

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

Mitigation only
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-48248

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

Mitigation only
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-48249

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

No fix yet
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-48250

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privile…

Mitigation only
Fix from $1,950 2023-05-09
Android HIGH 7.8
CVE-2022-44433

In phoneEx service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privi…

Mitigation only
Fix from $1,950 2023-05-09
Android MEDIUM 5.5
CVE-2022-47490

In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

Mitigation only
Fix from $1,600 2023-05-09
Android MEDIUM 5.5
CVE-2022-47492

In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

Mitigation only
Fix from $1,600 2023-05-09
Android MEDIUM 5.5
CVE-2022-47493

In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

No fix yet
Fix from $1,600 2023-05-09
Android MEDIUM 5.5
CVE-2022-38685

In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additiona…

No fix yet
Fix from $1,600 2023-05-09
Ipados HIGH 7.5
CVE-2023-27963

The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadO…

Fix: 9.4 / 12.6.4+
Fix from $1,950 2023-05-08
Django CRITICAL 9.8
CVE-2023-31047

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multipl…

Fix: 3.2.19 / 4.1.9+
Fix from $2,300 2023-05-07
GitLab HIGH 8.1
CVE-2023-0805

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, a…

Fix: 15.9.6 / 15.10.5+
Fix from $1,950 2023-05-03
Mattermost CRITICAL 9.1
CVE-2023-2193

Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code t…

Mitigation only
Fix from $2,300 2023-04-20
Android MEDIUM 5.5
CVE-2023-21091

In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This co…

Patch available
Fix from $1,600 2023-04-19
Android HIGH 7.8
CVE-2023-21094

In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due to a missing permission check…

Patch available
Fix from $1,950 2023-04-19
Android MEDIUM 5.5
CVE-2023-20909

In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local infor…

Mitigation only
Fix from $1,600 2023-04-19
Struxureware Data Center Expert HIGH 8.1
CVE-2023-25552

A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing…

Fix: after 7.9.2
Fix from $1,950 2023-04-18
W4 Post List MEDIUM 6.5
CVE-2023-1371

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which c…

Fix: 2.4.6+
Fix from $1,600 2023-04-17
Javascript Sdk MEDIUM 5.3
CVE-2023-29529

matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3401 group call is taking plac…

Fix: 24.1.0+
Fix from $1,600 2023-04-14
Turboscript MEDIUM 6.5
CVE-2023-30532

A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresp…

Fix: after 1.3
Fix from $1,600 2023-04-12
Report Portal MEDIUM 6.5
CVE-2023-30526

A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-sp…

Fix: after 0.5
Fix from $1,600 2023-04-12
Assembla Merge Request Builder MEDIUM 5.3
CVE-2023-30521

A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of …

Fix: after 1.1.13
Fix from $1,600 2023-04-12
Quay.io Trigger MEDIUM 5.3
CVE-2023-30519

A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding…

Fix: after 0.1
Fix from $1,600 2023-04-12
GitLab MEDIUM 5.3
CVE-2023-1167

Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions sta…

Fix: 15.8.5 / 15.9.4+
Fix from $1,600 2023-04-05
Nomad CRITICAL 9.8
CVE-2023-1782

HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where …

Fix: after 1.5.2
Fix from $2,300 2023-04-05