Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android HIGH 7.8
CVE-2022-39093

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution pri…

Mitigation only
Fix from $1,950 2022-12-06
Android HIGH 7.8
CVE-2022-39090

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution pri…

No fix yet
Fix from $1,950 2022-12-06
Stackstorm HIGH 7.5
CVE-2022-44009

Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V…

Mitigation only
Fix from $1,950 2022-12-06
Taskalfa 7550ci Firmware MEDIUM 6.5
CVE-2022-41807

Missing authorization vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to alter the …

Mitigation only
Fix from $1,600 2022-12-05
Rtl8111fp Cg Firmware MEDIUM 6.5
CVE-2022-32966

RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH s…

Fix: after 5.0.23
Fix from $1,600 2022-11-29
Ourphoto HIGH 7.5
CVE-2022-24190

The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implem…

No fix yet
Fix from $1,950 2022-11-28
Theme And Plugin Translation For Polylang MEDIUM 5.3
CVE-2022-4169

The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3.2.16 due to missing capabilit…

Fix: 3.2.17+
Fix from $1,600 2022-11-28
Xwiki HIGH 8.2
CVE-2022-41930

org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the…

Fix: 13.10.7 / 14.4.2+
Fix from $1,950 2022-11-23
Ckan HIGH 8.8
CVE-2022-43685

CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take o…

Fix: 2.8.12 / 2.9.7+
Fix from $1,950 2022-11-22
Xwiki HIGH 8.1
CVE-2022-41937

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view acce…

Fix: 13.10.8 / 14.4.3+
Fix from $1,950 2022-11-22
Micollab CRITICAL 9.8
CVE-2022-41326

The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper…

Fix: after 9.6.0.105
Fix from $2,300 2022-11-22
Appointment Booking Calendar HIGH 8.8
CVE-2022-43482

Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.

Fix: 1.3.70+
Fix from $1,950 2022-11-18
Appointment Hour Booking HIGH 8.8
CVE-2022-41692

Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress.

Fix: 1.3.72+
Fix from $1,950 2022-11-18
Consul HIGH 7.5
CVE-2022-3920

HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints us…

Fix: after 1.13.3
Fix from $1,950 2022-11-16
Secure Firewall Management Center MEDIUM 5.3
CVE-2022-20941

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,600 2022-11-15
Xp Dev MEDIUM 5.3
CVE-2022-45389

A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an at…

Fix: after 1.0
Fix from $1,600 2022-11-15
Cloudbees Docker Hub\/registry Notification HIGH 7.5
CVE-2022-45385

A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger…

Fix: 2.6.2.1+
Fix from $1,950 2022-11-15
Webmaster Tools Verification MEDIUM 6.5
CVE-2022-3538

The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenti…

Fix: after 1.2
Fix from $1,600 2022-11-14
Hyperic Server CRITICAL 9.8
CVE-2022-38651

A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some…

Mitigation only
Fix from $2,300 2022-11-12
Harmonyos HIGH 7.5
CVE-2022-44549

The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the g…

Mitigation only
Fix from $1,950 2022-11-09
Android HIGH 7.8
CVE-2022-20450

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. Thi…

Mitigation only
Fix from $1,950 2022-11-08
Android HIGH 7.8
CVE-2022-20451

In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local…

Mitigation only
Fix from $1,950 2022-11-08
Wp Hide MEDIUM 5.3
CVE-2022-3489

The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allow…

Fix: after 0.0.2
Fix from $1,600 2022-11-07
Simple Seo MEDIUM 5.4
CVE-2022-36404

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions.

Fix: after 1.8.12
Fix from $1,600 2022-11-03
Restaurant Menu Food Ordering System Table Reservation MEDIUM 6.5
CVE-2022-2696

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in…

Fix: 2.3.1+
Fix from $1,600 2022-11-03
Wp Total Hacks MEDIUM 5.4
CVE-2022-3096

The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users s…

Fix: after 4.7.2
Fix from $1,600 2022-10-31
Bricks MEDIUM 6.5
CVE-2022-3400

The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in version…

Fix: after 1.5.3
Fix from $1,600 2022-10-28
Warp Mobile Client HIGH 7.5
CVE-2022-3322

Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to ins…

Fix: 6.14+
Fix from $1,950 2022-10-28
Warp Mobile Client HIGH 8.5
CVE-2022-3337

It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflar…

Fix: 6.15+
Fix from $1,950 2022-10-28
Warp HIGH 8.8
CVE-2022-3512

Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trus…

Fix: 2022.8.857.0 / 2022.8.861.0+
Fix from $1,950 2022-10-28