Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Warp Mobile Client HIGH 8.2
CVE-2022-3321

It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#…

Fix: 6.14+
Fix from $1,950 2022-10-28
Warp CRITICAL 9.8
CVE-2022-3320

It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this comman…

Fix: 2022.8.857.0 / 2022.8.861.0+
Fix from $2,300 2022-10-28
Access Management MEDIUM 6.5
CVE-2022-24669

It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal networ…

Fix: after 7.0.2
Fix from $1,600 2022-10-27
Nextcloud Enterprise Server MEDIUM 5.3
CVE-2022-39329

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server pri…

Fix: 23.0.9 / 24.0.5+
Fix from $1,600 2022-10-27
Openfga MEDIUM 5.3
CVE-2022-39340

OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization head…

Fix: 0.2.4+
Fix from $1,600 2022-10-25
Lemon8 MEDIUM 6.5
CVE-2022-41797

Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versio…

Fix: 3.3.5+
Fix from $1,600 2022-10-24
Tug Home Base Server HIGH 8.2
CVE-2022-1066

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

Fix: 24+
Fix from $1,950 2022-10-21
Tug Home Base Server HIGH 8.1
CVE-2022-1070

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

Fix: 24+
Fix from $1,950 2022-10-21
Tug Home Base Server HIGH 7.5
CVE-2022-26423

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

Fix: 24+
Fix from $1,950 2022-10-21
Tuleap Git Branch Source MEDIUM 5.3
CVE-2022-43421

A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers to trigger Tuleap projects w…

Fix: 3.2.5+
Fix from $1,600 2022-10-19
Tuleap MEDIUM 5.4
CVE-2022-39233

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions 12.9.99.228 and above, prior to 14…

Fix: 13.12-6 / 14.0-3+
Fix from $1,600 2022-10-19
Discord Integration MEDIUM 6.5
CVE-2022-3082

The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logge…

Fix: 2.1.6+
Fix from $1,600 2022-10-17
Otrs HIGH 7.5
CVE-2022-3501

Article template contents with sensitive data could be accessed from agents without permissions.

Fix: 8.0.26+
Fix from $1,950 2022-10-17
Android MEDIUM 5.5
CVE-2022-39112

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privi…

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-39113

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privi…

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-39114

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privi…

No fix yet
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-39115

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privi…

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-39117

In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

No fix yet
Fix from $1,600 2022-10-14
Android HIGH 7.8
CVE-2022-39107

In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional …

No fix yet
Fix from $1,950 2022-10-14
Android HIGH 7.8
CVE-2022-39108

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privil…

No fix yet
Fix from $1,950 2022-10-14
Android HIGH 7.8
CVE-2022-39109

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privil…

No fix yet
Fix from $1,950 2022-10-14
Android HIGH 7.8
CVE-2022-39110

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privil…

No fix yet
Fix from $1,950 2022-10-14
Android HIGH 7.8
CVE-2022-39111

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privil…

No fix yet
Fix from $1,950 2022-10-14
Android MEDIUM 5.5
CVE-2022-38697

In messaging service, there is a missing permission check. This could lead to access unexpected provider in contacts service with no additional execu…

Mitigation only
Fix from $1,600 2022-10-14
Android HIGH 7.8
CVE-2022-38698

In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution…

No fix yet
Fix from $1,950 2022-10-14
Android HIGH 7.8
CVE-2022-39080

In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution…

Mitigation only
Fix from $1,950 2022-10-14
Android MEDIUM 5.5
CVE-2022-39103

In Gallery service, there is a missing permission check. This could lead to local denial of service in Gallery service with no additional execution p…

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-38679

In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privi…

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-38687

In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional executi…

No fix yet
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-38688

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2022-10-14