Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Ns Nd Integration Performance Publisher HIGH 8.8
CVE-2022-41228

A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permiss…

Fix: 4.8.0.130+
Fix from $1,950 2022-09-21
Rundeck HIGH 8.8
CVE-2022-41234

Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permissi…

Fix: after 3.6.11
Fix from $1,950 2022-09-21
Dotci CRITICAL 9.8
CVE-2022-41238

A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to th…

Fix: after 2.40.00
Fix from $2,300 2022-09-21
Extreme Feedback MEDIUM 5.4
CVE-2022-41242

A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information a…

Fix: after 1.7
Fix from $1,600 2022-09-21
Group Export MEDIUM 5.3
CVE-2022-39960EPSS 26%

The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to expo…

Fix: 1.0.3+
Fix from $1,600 2022-09-17
Fedora HIGH 7.8
CVE-2022-40673

KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.

Fix: 3.1.0+
Fix from $1,950 2022-09-14
Android HIGH 7.8
CVE-2022-39119

In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges nee…

Mitigation only
Fix from $1,950 2022-09-09
Xwiki HIGH 7.5
CVE-2022-36091

XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of…

Fix: 13.10.4 / 14.2+
Fix from $1,950 2022-09-08
Xwiki MEDIUM 6.5
CVE-2022-31167

XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.…

Fix: 12.10.11 / 13.4.6+
Fix from $1,600 2022-09-07
Transposh Wordpress Translation MEDIUM 5.3
CVE-2022-2461

The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, an…

Fix: after 1.0.8.1
Fix from $1,600 2022-09-06
User Export For Jira MEDIUM 5.3
CVE-2022-38367

The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to expor…

Fix: 2.0.6+
Fix from $1,600 2022-09-05
Directorist MEDIUM 5.3
CVE-2022-2376

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any au…

Fix: 7.3.1+
Fix from $1,600 2022-09-05
Visual Portfolio\, Photo Gallery \& Post Grid MEDIUM 6.1
CVE-2022-2543

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoint…

Fix: 2.18.0+
Fix from $1,600 2022-09-05
Iotdb HIGH 7.5
CVE-2022-38370

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users…

Mitigation only
Fix from $1,950 2022-09-05
Omnia Mpx Node Firmware CRITICAL 9.8
CVE-2022-36642EPSS 10%

A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users…

Fix: 1.5.0+
Fix from $2,300 2022-09-02
Simply Schedule Appointments MEDIUM 5.3
CVE-2022-2373

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retri…

Fix: 1.5.7.7+
Fix from $1,600 2022-08-29
Siteservercms HIGH 7.2
CVE-2022-36226

SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.

Fix: after 5.0.0
Fix from $1,950 2022-08-26
Avideo MEDIUM 5.0
CVE-2022-32769

Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A s…

Mitigation only
Fix from $1,600 2022-08-22
Duplicator MEDIUM 5.3
CVE-2022-2552EPSS 11%

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve…

Fix: 1.4.7.1+
Fix from $1,600 2022-08-22
Transposh Wordpress Translation MEDIUM 6.5
CVE-2022-25810

The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab …

Fix: after 1.0.8
Fix from $1,600 2022-08-22
Pycord MEDIUM 6.5
CVE-2022-36024

py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to remote shutdown if they are ad…

Patch available
Fix from $1,600 2022-08-18
Easy Student Results HIGH 7.5
CVE-2022-2379

The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information r…

Fix: after 2.2.8
Fix from $1,950 2022-08-15
Gitea MEDIUM 6.5
CVE-2022-38183

In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any i…

Fix: 1.16.9+
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20341

In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information dis…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20312

In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check. This could lead to local i…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20322

In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead to local information disclosur…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20323

In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lead to local information disclo…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20326

In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to local information disclosure wi…

Mitigation only
Fix from $1,600 2022-08-12
Android HIGH 7.8
CVE-2022-20329

In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead to local escalation of privile…

Mitigation only
Fix from $1,950 2022-08-12
Android MEDIUM 5.5
CVE-2022-20294

In Content, there is a possible way to learn about an account present on the device due to a missing permission check. This could lead to local infor…

Mitigation only
Fix from $1,600 2022-08-12