Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Wl Wn530hg4 Firmware HIGH 7.5
CVE-2022-48166

An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and …

No fix yet
Fix from $1,950 2023-02-06
My Cloud Os HIGH 8.8
CVE-2021-36225

Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads an…

Fix: 5.02.104+
Fix from $1,950 2023-02-06
Phpipam MEDIUM 5.3
CVE-2023-0678EPSS 37%

Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.

Fix: 1.5.1+
Fix from $1,600 2023-02-04
Print Away MEDIUM 5.4
CVE-2022-42909

WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This c…

Mitigation only
Fix from $1,600 2023-02-03
Femanager HIGH 7.5
CVE-2023-25014

An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the Invit…

Fix: 5.5.3 / 6.3.4+
Fix from $1,950 2023-02-02
Kraken.io Image Optimizer MEDIUM 6.5
CVE-2023-0619

The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in ver…

Fix: after 2.6.8
Fix from $1,600 2023-02-01
Wire MEDIUM 6.5
CVE-2023-22737

wire-server provides back end services for Wire, a team communication and collaboration platform. Prior to version 2022-12-09, every member of a Conv…

Fix: 2022-12-09+
Fix from $1,600 2023-01-28
Contentstudio MEDIUM 6.5
CVE-2023-0556

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to…

Fix: 1.2.6+
Fix from $1,600 2023-01-27
Netmatch S Ci CRITICAL 9.1
CVE-2022-39811

Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not ve…

No fix yet
Fix from $2,300 2023-01-27
Quick Restaurant Menu HIGH 8.1
CVE-2023-0555

The Quick Restaurant Menu plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in version…

Fix: 2.1.0+
Fix from $1,950 2023-01-27
Bearychat MEDIUM 6.5
CVE-2023-24459

A missing permission check in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec…

Fix: after 3.0.2
Fix from $1,600 2023-01-26
Rabbitmq Consumer MEDIUM 6.5
CVE-2023-24448

A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permission to connect to an attacke…

Fix: after 2.8
Fix from $1,600 2023-01-26
Testquality Updater MEDIUM 6.5
CVE-2023-24453

A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifi…

Fix: after 1.3
Fix from $1,600 2023-01-26
Orka By Macstadium MEDIUM 6.5
CVE-2023-24433

Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Overall/Read permission to connect to an attacke…

Fix: 1.32+
Fix from $1,600 2023-01-26
Github Pull Request Builder MEDIUM 6.5
CVE-2023-24435

A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to connect …

Fix: after 1.42.2
Fix from $1,600 2023-01-26
Jira Pipeline Steps MEDIUM 6.5
CVE-2023-24438

A missing permission check in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers with Overall/Read permission to c…

Fix: after 2.0.165.v8846cf59f3db
Fix from $1,600 2023-01-26
Xblock Lti Consumer MEDIUM 5.4
CVE-2023-23611

LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and …

Fix: 7.2.2+
Fix from $1,600 2023-01-26
Argo Cd HIGH 8.5
CVE-2023-22736

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, prior to 2.5.8, and version 2.6…

Fix: 2.5.8+
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2023-20912

In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due to a missing permission check…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2023-20916

In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starting activities from the backgr…

Mitigation only
Fix from $1,950 2023-01-26
GitLab MEDIUM 5.3
CVE-2022-3482

An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 all…

Fix: 15.4.6 / 15.5.5+
Fix from $1,600 2023-01-26
Events Made Easy MEDIUM 5.4
CVE-2023-0404

The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJA…

Fix: after 2.3.16
Fix from $1,600 2023-01-19
Social Warfare MEDIUM 5.4
CVE-2023-0402

The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions u…

Fix: after 4.3.0
Fix from $1,600 2023-01-19
Velociraptor HIGH 8.8
CVE-2023-0242

Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on th…

Fix: 0.6.7-5+
Fix from $1,950 2023-01-18
Blogengine.net CRITICAL 9.8
CVE-2022-41417

BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.

Patch available
Fix from $2,300 2023-01-18
G955v1 Firmware MEDIUM 6.8
CVE-2020-22007

OS Command Injection vulnerability in OKER G955V1 v1.03.02.20161128, allows physical attackers to interrupt the boot sequence and execute arbitrary c…

No fix yet
Fix from $1,600 2023-01-18
Kubepi HIGH 7.5
CVE-2023-22478

KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in…

Fix: 1.6.4+
Fix from $1,950 2023-01-14
Flarum MEDIUM 5.4
CVE-2023-22488

Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private content and bypass access check…

Fix: 1.6.3+
Fix from $1,600 2023-01-12
Android MEDIUM 5.5
CVE-2022-44438

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional executio…

Mitigation only
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-44439

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional executio…

Mitigation only
Fix from $1,600 2023-01-04