Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2022-38689

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2022-10-14
Android HIGH 7.8
CVE-2022-38669

In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execu…

No fix yet
Fix from $1,950 2022-10-14
Android HIGH 7.8
CVE-2022-38670

In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execu…

Mitigation only
Fix from $1,950 2022-10-14
Android MEDIUM 5.5
CVE-2022-38677

In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privile…

No fix yet
Fix from $1,600 2022-10-14
Android HIGH 7.8
CVE-2022-2985

In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution pri…

No fix yet
Fix from $1,950 2022-10-14
Openharmony HIGH 7.8
CVE-2022-42488

OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious applicat…

Fix: 3.1.2+
Fix from $1,950 2022-10-14
Airframe Bmc Web Gui R18 Firmware HIGH 8.8
CVE-2022-28866

Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for acc…

Fix: 4.13.00+
Fix from $1,950 2022-10-12
Android HIGH 7.8
CVE-2022-20430

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p…

No fix yet
Fix from $1,950 2022-10-11
Android HIGH 7.8
CVE-2022-20431

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p…

Mitigation only
Fix from $1,950 2022-10-11
Android HIGH 7.8
CVE-2022-20432

There is an missing authorization issue in the system service. Since the component does not have permission check and permission protection,, resulti…

Mitigation only
Fix from $1,950 2022-10-11
Android HIGH 7.8
CVE-2022-20433

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p…

Mitigation only
Fix from $1,950 2022-10-11
Android HIGH 7.8
CVE-2022-20434

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p…

Mitigation only
Fix from $1,950 2022-10-11
Android MEDIUM 5.0
CVE-2022-20394

In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due t…

Patch available
Fix from $1,600 2022-10-11
6gk6108 4am00 2ba2 Firmware HIGH 8.8
CVE-2022-31765

Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate thei…

Fix: 7.1.2+
Fix from $1,950 2022-10-11
Disable User Login MEDIUM 5.3
CVE-2022-2350

The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticate…

Fix: after 1.0.1
Fix from $1,600 2022-10-10
Zoneminder HIGH 7.5
CVE-2022-39289

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log conten…

Fix: 1.37.24+
Fix from $1,950 2022-10-07
Dex MEDIUM 6.5
CVE-2022-39222

Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clie…

Fix: 2.35.0+
Fix from $1,600 2022-10-06
Frontend File Manager MEDIUM 5.3
CVE-2022-3124EPSS 7%

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due t…

Fix: 21.3+
Fix from $1,600 2022-10-03
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15337

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15338

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.

No fix yet
Fix from $1,600 2022-09-29
Ldap Wp Login \/ Active Directory Integration HIGH 7.5
CVE-2022-2987

The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's set…

Fix: 3.0.2+
Fix from $1,950 2022-09-26
Scripts Organizer HIGH 8.8
CVE-2021-24890

The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthent…

Fix: 3.0+
Fix from $1,950 2022-09-26
Mailoptin MEDIUM 5.3
CVE-2022-36340

Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress.

Fix: after 1.2.49.0
Fix from $1,600 2022-09-23
Rocket.chat MEDIUM 6.5
CVE-2022-32220

An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from pr…

Fix: 5.0+
Fix from $1,600 2022-09-23
Consul HIGH 7.1
CVE-2021-41803

HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT cl…

Fix: 1.11.9+
Fix from $1,950 2022-09-23
System Center Configuration Manager MEDIUM 5.3
CVE-2021-39190

The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is…

Fix: 2.3.0+
Fix from $1,600 2022-09-22
Dxp MEDIUM 6.5
CVE-2022-38512

The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allow…

Fix: after 7.4.3.36
Fix from $1,600 2022-09-22
Worksoft Execution Manager MEDIUM 6.5
CVE-2022-41246

A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Overall/Read permission to conne…

Fix: after 10.0.3.503
Fix from $1,600 2022-09-21
Scm Httpclient MEDIUM 6.5
CVE-2022-41250

A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-s…

Fix: after 1.5
Fix from $1,600 2022-09-21
Cons3rt MEDIUM 6.5
CVE-2022-41254

Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specifie…

Fix: after 1.0.0
Fix from $1,600 2022-09-21