Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2022-20295

In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local in…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20296

In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local in…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20298

In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local in…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20299

In ContentService, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to l…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20300

In Content, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local in…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20301

In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local informati…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20303

In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission ch…

Mitigation only
Fix from $1,600 2022-08-12
Android HIGH 7.8
CVE-2022-20274

In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User executi…

Mitigation only
Fix from $1,950 2022-08-12
Android HIGH 7.8
CVE-2022-20281

In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of p…

Mitigation only
Fix from $1,950 2022-08-12
Android HIGH 7.8
CVE-2022-20282

In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation…

Mitigation only
Fix from $1,950 2022-08-12
Android MEDIUM 5.5
CVE-2022-20284

In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of phone …

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20259

In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no ad…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20263

In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disc…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2021-0735

In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced in Android 11 due to a missing…

Mitigation only
Fix from $1,600 2022-08-11
Enable Now Manager CRITICAL 9.1
CVE-2022-35293

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, a…

Mitigation only
Fix from $2,300 2022-08-10
Android HIGH 7.8
CVE-2022-20360

In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the g…

Patch available
Fix from $1,950 2022-08-10
Android HIGH 7.8
CVE-2022-20348

In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission che…

Patch available
Fix from $1,950 2022-08-10
Android HIGH 7.8
CVE-2022-20349

In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permissi…

Patch available
Fix from $1,950 2022-08-10
Android MEDIUM 5.5
CVE-2022-20352

In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a m…

Patch available
Fix from $1,600 2022-08-10
Openemr HIGH 8.3
CVE-2022-2732

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.

Fix: 7.0.0.1+
Fix from $1,950 2022-08-09
Discy MEDIUM 6.5
CVE-2022-1323

The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logge…

Fix: 5.0+
Fix from $1,600 2022-08-08
Charm Firmware MEDIUM 5.5
CVE-2022-36836

Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.

Fix: 1.2.3+
Fix from $1,600 2022-08-05
Tuleap MEDIUM 5.4
CVE-2022-31128

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not properly …

Fix: 13.10-3 / 13.10.99.82+
Fix from $1,600 2022-08-01
Android HIGH 7.8
CVE-2022-26429

In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2022-08-01
Yaysmtp MEDIUM 6.5
CVE-2022-2370

The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowi…

Fix: 2.2.1+
Fix from $1,600 2022-08-01
Coverity HIGH 8.1
CVE-2022-36921

A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec…

Fix: after 1.11.4
Fix from $1,950 2022-07-27
Openshift Deployer MEDIUM 6.5
CVE-2022-36907

A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to connect to an atta…

Fix: after 1.2.0
Fix from $1,600 2022-07-27
Openshift Deployer MEDIUM 6.5
CVE-2022-36909

A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to check for the exis…

Fix: after 1.2.0
Fix from $1,600 2022-07-27
Lucene Search MEDIUM 5.4
CVE-2022-36910

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Ove…

Fix: after 370.v62a5f618cd3a
Fix from $1,600 2022-07-27
Hashicorp Vault MEDIUM 6.5
CVE-2022-36888

A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain …

Fix: after 354.vdb_858fd6b_f48
Fix from $1,600 2022-07-27