Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2022-20206

In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclos…

Mitigation only
Fix from $1,600 2022-06-15
Android MEDIUM 5.5
CVE-2022-20172

In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local informati…

Mitigation only
Fix from $1,600 2022-06-15
Android HIGH 7.8
CVE-2022-20138

In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVIS…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.3
CVE-2022-20126

In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permissio…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.8
CVE-2022-20133

In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead t…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.3
CVE-2022-20137

In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permissi…

Patch available
Fix from $1,950 2022-06-15
Adaptive Server Enterprise HIGH 8.8
CVE-2022-31595

SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of pri…

Mitigation only
Fix from $1,950 2022-06-14
Couchbase Server HIGH 7.5
CVE-2022-32560

An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.

Fix: 7.0.4+
Fix from $1,950 2022-06-13
Emui MEDIUM 5.5
CVE-2022-31752

Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality.

No fix yet
Fix from $1,600 2022-06-13
Filr HIGH 8.8
CVE-2022-1777

The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticate…

Fix: 1.2.2.1+
Fix from $1,950 2022-06-13
Like Button Rating MEDIUM 6.5
CVE-2022-0745

The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with…

Fix: 2.6.45+
Fix from $1,600 2022-06-13
Member Hero CRITICAL 9.8
CVE-2022-0885EPSS 9%

The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing …

Fix: after 1.0.9
Fix from $2,300 2022-06-13
Enqueue Anything MEDIUM 6.5
CVE-2021-25116

The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure …

Fix: after 1.0.1
Fix from $1,600 2022-06-13
Files Download Delay MEDIUM 6.5
CVE-2022-1570

The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any …

Fix: 1.0.7+
Fix from $1,600 2022-06-08
Smartthings HIGH 7.5
CVE-2022-30746

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface AP…

Fix: 1.7.85.12+
Fix from $1,950 2022-06-07
My Files MEDIUM 5.5
CVE-2022-30731

Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files applica…

Fix: 13.1.00.193+
Fix from $1,600 2022-06-07
Android MEDIUM 5.5
CVE-2022-21748

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User…

Mitigation only
Fix from $1,600 2022-06-06
Android MEDIUM 5.5
CVE-2022-21749

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no a…

Mitigation only
Fix from $1,600 2022-06-06
Elastic Storage System CRITICAL 9.1
CVE-2020-4926

A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection…

Fix: 5.1.3.0 / 6.1.3.0+
Fix from $2,300 2022-05-24
Multi Store Inventory Management System CRITICAL 9.8
CVE-2022-28993

Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.

No fix yet
Fix from $2,300 2022-05-20
GitLab HIGH 8.8
CVE-2022-1423

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9…

Fix: 14.8.6 / 14.9.4+
Fix from $1,950 2022-05-19
A1 Firmware MEDIUM 5.3
CVE-2021-42848

An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrie…

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,600 2022-05-18
A1 Firmware MEDIUM 5.3
CVE-2021-42851

A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,600 2022-05-18
Ssh MEDIUM 6.5
CVE-2022-30959

A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified …

Fix: after 2.6.1
Fix from $1,600 2022-05-17
Wmi Windows Agents HIGH 8.8
CVE-2022-30951

Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing…

Fix: 1.8.1+
Fix from $1,950 2022-05-17
Blue Ocean MEDIUM 6.5
CVE-2022-30954

Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read perm…

Fix: after 1.25.3
Fix from $1,600 2022-05-17
GitLab MEDIUM 6.5
CVE-2022-30955

Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to …

Fix: after 1.5.31
Fix from $1,600 2022-05-17
Mypro HIGH 7.5
CVE-2021-33013

mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.

Fix: 8.20.0+
Fix from $1,950 2022-05-13
Linux Kernel HIGH 7.8
CVE-2022-30594

The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting…

Fix: 4.19.238 / 5.4.189+
Fix from $1,950 2022-05-12
Netweaver Application Server Abap HIGH 8.8
CVE-2022-29611

SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in esc…

Mitigation only
Fix from $1,950 2022-05-11