Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2022-44422

In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution pr…

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-44423

In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution pr…

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-44424

In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution pr…

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-44434

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional executio…

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-44435

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional executio…

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-44436

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional executio…

Mitigation only
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-44437

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional executio…

Mitigation only
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39086

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39087

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

Mitigation only
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39088

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

Mitigation only
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-39104

In contacts service, there is a missing permission check. This could lead to local denial of service in Contacts service with no additional execution…

Mitigation only
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-38678

In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution…

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-38682

In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution…

Mitigation only
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-38683

In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution…

Mitigation only
Fix from $1,600 2023-01-04
Android MEDIUM 5.5
CVE-2022-38684

In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution…

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39081

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39082

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39083

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39084

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Android MEDIUM 6.7
CVE-2022-39085

In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

No fix yet
Fix from $1,600 2023-01-04
Iubenda Cookie Law Solution HIGH 8.8
CVE-2022-3911

The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be upd…

Fix: 3.3.3+
Fix from $1,950 2023-01-02
Webpanel CRITICAL 9.8
CVE-2021-45467EPSS 71%

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to regi…

Fix: 0.9.8.1107+
Fix from $2,300 2022-12-26
Firefox MEDIUM 6.5
CVE-2022-45410

When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Directorist MEDIUM 6.5
CVE-2022-3961

The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system informati…

Fix: 7.4.4+
Fix from $1,600 2022-12-19
Pie Register MEDIUM 6.5
CVE-2022-4024

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing …

Fix: 3.8.1.3+
Fix from $1,600 2022-12-19
Paydroid MEDIUM 6.8
CVE-2022-26581

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the execution …

Mitigation only
Fix from $1,600 2022-12-16
Android MEDIUM 6.7
CVE-2022-20572

In verity_target of dm-verity-target.c, there is a possible way to modify read-only files due to a missing permission check. This could lead to local…

Patch available
Fix from $1,600 2022-12-16
Android HIGH 7.8
CVE-2022-20547

In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lea…

Patch available
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20522

In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user wit…

Patch available
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20503

In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission che…

Patch available
Fix from $1,950 2022-12-16