Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Compuware Source Code Download For Endevor\, Pds\, And Ispw MEDIUM 6.5
CVE-2022-36896

A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overa…

Fix: after 2.0.12
Fix from $1,600 2022-07-27
Git HIGH 7.5
CVE-2022-36883EPSS 6%

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an a…

Fix: after 4.11.3
Fix from $1,950 2022-07-27
Qq HIGH 7.5
CVE-2021-33057

The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determi…

No fix yet
Fix from $1,950 2022-07-26
Ftmg Firmware MEDIUM 5.3
CVE-2021-32504

Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker c…

Fix: 2.8+
Fix from $1,600 2022-07-19
Buddypress Group Reviews MEDIUM 5.3
CVE-2022-2108

The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missi…

Fix: 2.8.4+
Fix from $1,600 2022-07-18
Android MEDIUM 5.5
CVE-2022-20225

In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This…

Patch available
Fix from $1,600 2022-07-13
S\/4hana MEDIUM 5.4
CVE-2022-31597

Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does n…

Mitigation only
Fix from $1,600 2022-07-12
Keycloak CRITICAL 9.8
CVE-2022-1245

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…

Fix: 18.0.0+
Fix from $2,300 2022-07-08
Android MEDIUM 5.5
CVE-2022-21763

In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure wit…

Mitigation only
Fix from $1,600 2022-07-06
Android MEDIUM 5.5
CVE-2022-21764

In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure wit…

Mitigation only
Fix from $1,600 2022-07-06
Android HIGH 7.8
CVE-2022-21777

In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additi…

Mitigation only
Fix from $1,950 2022-07-06
Rqm MEDIUM 6.5
CVE-2022-34810

A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials store…

Fix: after 2.8
Fix from $1,600 2022-06-30
Recipe MEDIUM 6.5
CVE-2022-34794

Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacke…

Fix: after 1.2
Fix from $1,600 2022-06-30
Xebialabs Xl Release MEDIUM 6.5
CVE-2022-34781

Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an att…

Fix: after 22.0.0
Fix from $1,600 2022-06-30
Armember HIGH 8.1
CVE-2022-1903EPSS 9%

The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks i…

Fix: 3.4.8+
Fix from $1,950 2022-06-27
Html2wp HIGH 8.1
CVE-2022-1572

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such a…

Fix: after 1.0.0
Fix from $1,950 2022-06-27
Html2wp CRITICAL 9.8
CVE-2022-1574EPSS 12%

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result,…

Fix: after 1.0.0
Fix from $2,300 2022-06-27
Local Run Manager CRITICAL 9.1
CVE-2022-1521

LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.

Fix: after 3.1
Fix from $2,300 2022-06-24
Vrealize Orchestrator MEDIUM 5.7
CVE-2022-34212

A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST…

Fix: after 3.0
Fix from $1,600 2022-06-23
Convertigo Mobile Platform MEDIUM 6.5
CVE-2022-34201

A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to a…

Fix: after 1.1
Fix from $1,600 2022-06-23
Threadfix MEDIUM 6.5
CVE-2022-34210

A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec…

Fix: after 1.5.4
Fix from $1,600 2022-06-23
Sihas Sgw 300 Firmware CRITICAL 9.8
CVE-2021-26637

There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized…

Mitigation only
Fix from $2,300 2022-06-23
Erpnext MEDIUM 5.5
CVE-2022-23055

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker…

Fix: 13.1.0+
Fix from $1,600 2022-06-22
Discourse Chat MEDIUM 6.5
CVE-2022-31095

discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an…

Fix: 0.4+
Fix from $1,600 2022-06-21
Mahara HIGH 7.5
CVE-2022-33913

In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

Fix: 21.04.6 / 21.10.4+
Fix from $1,950 2022-06-20
Xos Shop System HIGH 8.1
CVE-2021-46820

Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/categories.php

No fix yet
Fix from $1,950 2022-06-16
Xos Shop System HIGH 8.1
CVE-2021-37764

Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/manufacturers.php.

Mitigation only
Fix from $1,950 2022-06-16
Appdynamics Controller MEDIUM 5.3
CVE-2022-20736

A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to acc…

Fix: 21.4.7+
Fix from $1,600 2022-06-15
Android MEDIUM 5.5
CVE-2022-20200

In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local informa…

Mitigation only
Fix from $1,600 2022-06-15
Android HIGH 7.8
CVE-2022-20204

In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permi…

Mitigation only
Fix from $1,950 2022-06-15